“Calhoun 


Institutional Archive of the Naval Postgraduate School 





Calhoun: The NPS Institutional Archive 
DSpace Repository 


Theses and Dissertations 1. Thesis and Dissertation Collection, all items 


1978 


Control systems reliability using redundant instrumentatic 


Loule, Chuck Long 


Massachusetts Institute of Technology 


http://hdl.handle.net/10945/28071 


Downloaded from NPS Archive: Calhoun 


| Calhoun is the Naval Postgraduate School's public access digital repository for 
D U DLEY research materials and institutional publications created by the NPS community. 
qe Calhoun is named for Professor of Mathematics Guy K. Calhoun, NP3's first 
KNOX appointed — and published — scholarly author. 





LIBRARY Dudley Knox Library / Naval Postgraduate School 
411 Dyer Road / 1 University Circle 


http://www.nps.edu/library Monterey, California USA 93943 








SS KN Ostana ADUATE ae 
ATE SCHOOL 
eer SPY, 93949 

















CONEROL SYSTEMS RELIABILITY 
USING REDUNDANT INSTRUMENTATION 


by 
CHUCK LONG LOUIE 
Lieutenant, United States Navy 
B.S.E.E., United States Naval Academy 
(1975) 
SUBMITTED TO THE DEPARTMENT OF 
OCEAN ENGINEERING IN 
PARTIAL FULFILLMENT OF THE REQUIREMENTS 
FOR THE DEGREES OF 
OCEAN ENGINEER 
and 
MASTER OF SCIENCE IN MECHANICAL ENGINEERING 


at the 
MASSACHUSBRITIS INSTITUTE OF TECHNOLOGY 


June 1982 
(c) Chuck Long Louie 1982 


The author hereby grants to M.I.T. permission to reproduce 
and to distribute copies of this thesis document in whole 
Qp. Ln panta, 


2 





CONTROL SYSTEWSWREDTADILITY 


USING REDUNDANT INSTRUMENTATION 


by 
CHUCK LONC LOUIE 


SID Cedro the Department of Ocean Engineering 
on May 7, 1982 in partial fulfillment of the 
requirements for the degrees of 
Ocean Engineer and Master of Science 


in Mechanical Engineering 


ABSTRACT 


This thesis examines the increase in reliability 
of a thermal power control system by using redundant 
temperature and pressure instrumentation. This 
improvement in reliability can be accomplished by 
applying various multiplexing techniques to the noisy 
signals from a set of redundant instrument channels. 
Multiplexing techniques such as averaging, mediating, 
and voting based on weight factors will be examined 
in detail along with probabilistic analysis and 
experimental verifications. The effect of multiplexing 
on noise reduction will also be discussed, And finally, 
the area of instrument error distribution within a 
real-time system is briefly introduced to provide basis 
tor zutrure work. 


Thesis Supervisor: Dr. Henry M. Paynter 
Title : Professor of Mechanical Engineering 





ACKNOWLEDGEMENTS 


The author would like to express his most sincere appre- 
action to Professor Henry M. Paynter for all of his encour- 
agement, advice, and endless enthusiasm during the entire 
acion Of this thesis. The many discussions of long hours 
Beıcache aucnor Nad with Prof. Paynter were proven to be most 
WééCcful and enlightening as well. 


The author's interest in control systems instrumentation 
stems from a comprehensive survey that he conducted on flow 
Pasoruments under the supervision of Prof. Paynter the year 
Before. It was only with Prof. Paynter's great enthusiasm 
at the outset of this thesis, however, that the author decided 
TO undertake the task Of writing a thesis in this area. 


WW=addlEton, the author is most grateful to his wife, 
Bela, for all of her support during the writing of this 
mesis, including the typing of the entire manuscript ina 
mest dedicated manner. Her interest in the author's work and 
Br zeneourazement during: difficult times greatly contributed 
to the author's ability in completing this thesis. 





Abstract 


"r T 


TABLE OF CONTENTS 


Mr RSS, +. 6 o o o o o o o e o 


mico £ Contents +». +» . è è è è > o o o oœ 


List of Figures è ° ° ° ə ° ° ° ° ° è . ° 


List OL Tables o ° * o o o o o o ° ® o o o 


Preface 


o o O o 0 0 o e o o 0 o o o £ o o 


S LONS . o e o è o o o o è o è o o o 


wer I. Introduction to Engineering 


Ca DA. ç « « «© ə « > 
WaGroduetten . , . . . .s « « 
Re ros Tor tFaulu=tolernanmce . . . 
Implementation of Fault-tolerance 


mae Author's Position on Type of 
Sendo Tap Processed ... è e o 


ehapter II. Instrumentation Errors and 


Vie + « « « `° 
ES Fells «6 6 6 6 6 « « 
Resistance Temperature Detectors 
Eee 
Dose zNetalzThermocouples . . . +. 


Variable Resistance Pressure 
Ti N (JI S YS s > s e > s o o > o o 


Diaphragm-Type Variable Reluctance 
a el + s e e ° ° 


Piezoelectric Pressure Transducers 


Page 


TO 
Tr 


L3 


14 
14 
i7 


eu 


28 


Sil 
Sel 
32 
25 


S 


40 


42 


43 





Tie OF CONTENTS (CONTINUED) 


Page 
H. Vibration Type Liquid Densitometer ...... 44 
IN OA EAREmarkS  . e è +. © 2 o « «© © e > o o 45 
MSc Tit T Probabi mistic Begles , . + è è 60 2 è > è o 47 
o II 0 00 0 0 0 + 47 
Lello To Ən Aucomata le «6 « « ella « © « « < è è 47 
vo) ec iO SO MIL ULOLCKINIP o >s > s e < < «© o 48 
Dre Or ND IST i S Ma JO rity Organ . è. < < « « > è è 50 
E. Majority Organ Operations in 
cone ee _ _ , 4 < « e © © © © ° 54 
e e Aa TG Aa TETO e a _ `, < «© «© «© « © © «© 0 36 
G. Analogy Among Binary, Multi-valued, | 
Ceo n os ELOS “So. + 6 « « « © « « °. . . > 
H. From Digital to Analog via Multi- 
eee ones N. + + <+ » ¿e 6 © © © « è è 60 
Do COI GING a a « , « © © © e. © © « ° ol 
we Operations of the Majority Organ 
eaea OE a E nen BEE 
Chapter IV. Averaging, Mediating, and er 
Deren OM I.  _ < <ç <s s s 0 o 66 
DES CORE ROUND e o , 2 < < © è o o o oè > 66 
Bem Transition from Digital to 
Puo e oe Dee s 5 6 tl lel ll o. . mo. e 67 
Cee S Opis Multiplexing Technique . «è» è è de ə sa 69 
INF G s T OI e <s < < e e © © 6 « 6 N 


Peemevemced Voter Technique . . . + è < < < < e e 91 





DESEE OF CONTENTS (CONTINUED) 


Pune cional Redundancy . . . . < < ə ° 


AS Le Example in Multiplexing . . 


Dee. Island Sewage Treatment 


Plant - A Revisited Case Study . . 


(CCI Son Rol Panel s a è + è è e 


A Need for Newer Je as e ce 


Insufficient Instrumentation for 


F. 
C MOi Sei Reduction . . 
H: 

Wiapter V. 
U POGUCETON e s.» 
B System Description 
Co Sewage Tunnel System 
D. 
DIR 
Cei tal Telemetry + 
G. 
FI, Instrumentation Fornire 


Srapcer Vi. 


Electrical Generators . è» è è ə ə è >œ 


Introduction 


PONS COrreEecCtion 


Physical Constraints Imposed 
Dy Constitutive 
Relationships: 

Instrumentation 


and Conservation 
Implication for 
Redundancy > . . 


o 0 e o o e o e o 


ER COFTECLIÓN . è è e è ə è 


How to Minimize Data Error in 


a 2-Phase Region 


e ° o o è o o e e 


An Example in Minimization of 


Data Error 


97 


TOS 


109 
OS 
nO? 
I 
Ti. 
120 


220 


reo 


ay 


co 
T29 
129 


oe 


1 o 


134 





TABLE OF CONTENTS (CONTINUED) 


De ant Parameters — T, P, O +». . e e e = = + 157 


G. The Role of Conservation Laws 
leet CMe US a. m © « o ò è o o 139 


A a e +. e... .. . ... ............. 1744 


Appendix I: Various Temperature and Pressure 
SENSORS ee a 150 





SE RE 


æ 


AOL CO ASS Lem Ov] è è < è è è 
Audio rnatonMastalBlack BOX . . è è è è o 
re or 0 e 0 0 è « « « 


Numerical Evaluation of the 
ge 0 , 4 e + e 6 « « « 


ea aons Or Union and Intersection . 


Union and Intersection of a 
Binary Wo rd ° 0 o 0 o 0 0 0 0 0 o o 0 


A II a esas < «© ° 
Sales among Different Loglcs  . 
Selection as a Process . . . è è è < œ 


Operavlons of the Upper and 
Meme elec tons h a a 6 6) 6 6 « «6 . ° 


T Rode line oit tne Majority Organ . 
eon o ICoOon i nuous Median Signal 
ieee icp lexed System , + + e è o 
DES ORA è è è è < «© e < è 


Normalized Distribution of 
ee enal (X) s e e sre o o o o o 


ASOC. s o s s © « “4 o o o 
P C y e 5. < è e e e e “€ “ e 
A 3-Bit Voter © e o e o ° . ° ° o © © 


r eobobilircy Of Failure for a 
ecnannel oi  . 5 ee ar «© « 


MOLI 6. 4 <+ < « «© «© «© © «© . 


50 


53 


54 


DO 


SH 


58 


62 


63 


64 


65 


gel 


Coi 


80 


34 


Ə Z 





4.11 


4.12 


eS 


4.14 


LIST OF FIGURES (CONTINUED) 


MU ote Line Restoring Organ . 
estes Voting Technique . . 
mies vs. Levels of Voting .. 
NACO AIVOT , + è è è © 0 e o 
Pense ronal Redundancy è. è ə è è. 
Averaging an Aperiodic Waveform 
Averaging 5ySCem Wavetorms , + + 
breed Band NoiSe . . è è è e è è 
Narrow Band Noise Een, 
AC 5 «© < 6 6 © «© © © 8 
Pomoc Example in Multiplexing 


The Deer Island Plant and How It 


Semece Tummel System ....«. - 


Deer Island Telemetry System 
Gurzemt iz ımüse) . so... 6 . <+ 


e lors Coled Status Board ,.-. < . 
lembi Telemecry System . . 
fa Cs 3] Pressure Cell... 
Dez—WasemBe2s]j]on , è + > 0 è è è 
ARO PS SSUBement . . . . . . . ° 
Biecssume MesSuUrement . . . è è +. 


pue He Erenanger . +. è + 


90 


s 


Sui 


100 


TOT 


DOS 


103 


106 


1 2 


TES 


117 


119 


MAS 


130 


132 


140 


141 


141 





= So 


LIST OFF BER > 


O alibration Drift Test Results . è è è + 


uu Voter Output Tor Triply Redundant Signals 


o 





E a E° 


PREFACE 


An orten utilized technique to increase the reliability 
any Control system is the use of redundancy. The art of 
redundancy, however, comes in many variations. It could 
be redundancy in the software, like a back-up computer 
program package in an interplanetary spacecraft; or it could 
be redundancy in the hardware, like a set of triply redun- 
dant signal processing channels, as is the case in this thesis. 

A system that uses redundancy to increase its overall 
reliability is sometimes referred to as "a fault-tolerant 
system". Fault-tolerance is the unique attribute of a control 
system which makes it possible for the system to continue with 
‘its program-specified behavior as a logic machine after the 
Becurrence of faults. 

One area of engineering that the application of redundancy 
has been mostly neglected is the redundancy of primary instru- 
mentation in a thermal power system. Without redundancy, 
igiene one and only instrument fails, the entire control system 
will more than likely malfunction. One must recognize the 
tremendous amount of revenue at stake when a power plant is 
shutdown due to a simple instrument failure. 

In this thesis the author will first present an overview 
of the principle of fault-tolerance, its incentives and 
methods of implementation (chapter 1). In chapter 2 a study 


will be conducted on the errors and uncertainties of 





Zus 


instrument measurements obtained through temperature and 
pressure instrumentation. The area of probabilistic logics 
as applied in instrumentation redundancy will be discussed 
in chapter 3. Next, the author will demonstrate how the 
techniques of averaging and voting would significantly 
improve the quality of the signals and increase the reliabi- 
lity of such redundant instrumentation system (chapter 4). 
In chapter 5 a case study of some of the unique and highly 
reliable control systems at the Deer Island Sewage Treatment 
Plant will be presented. And finally in chapter 6, the 
method of using constitutive and conservation laws to 


minimize measurement errors will be briefly examined. 





= 


CONCLUSIONS 


Deznoschesreehniques Of avenmardmo, mediating, and voting, 
K is Little doubt that the overall reliability has been 
greatly increased for a control system using redundant 
instrumentation. In order to maximize the full advantages of 
fault-tolerance, however, one must devote complete attention 
to the implementation of redundant hardware at the outset of 
system design. 

Mecane concluded that murtiplexing techniques such 
as averaging and voting can indeed increase the reliability 
of any redundant instrumentation system, as shown by pro- 
babilistic analysis and experimental verifications. Moreover, 
the implementation of such techniques is easily realizable, 
as the author has illustrated with an example. Furthermore, 
Ku Lo the high frequency spectral content of a voter output, 
MN cechnique of multiplexing can actually be utilized to 
simplify the task of noise reduction. 

And finally as indicated in chapter 6, instrument error 
distribution within a real-time system is indeed an important 
aspect of redundant instrumentation. Much more work needs to 


be done in this area, 





AE 


CHAPTER I. 


CO ODUCTTON TO ENGINEERING OF RELIABILITY 


A. Triesoducekion 
If for example one simply instalis a redundant 

instrument at the temperature sensing point in a thermal 
power plant, there is no question that the reliability of 
the temperature measurement has been increased. This is 
men cO the simple fact that if one instrument malfunctions, 
a second instrument is still available to measure the para- 
meter. However, if one ponders for a moment, he begins to 
wonder if he could improve the quality of the measurements at 
all times, even when there is no instrumentation malfunction 
at all., This question is especially valid if one recognizes 
the fact that temperature sensing devices come in many differ- 
ent types, e.g. RTDs, thermistors, and thermocouples; all of 
these instruments have their own inherent errors and uncertain- 
mes. Could one improve the quality of the measurements so 
that the output signal is always equal to the best of the 
signals from the different primary sensors? The answer is, 
"Yes, a fault-tolerant system can do just that". The reader 
Will see why in the pages to follow. 

Fauft-tolerance is the architectural attribute of a di- 
gital system that keeps the logic machine doing its specified 
tasks when its host, the physical system, suffers various 


(1) 


kinds of failure of its components. A fault-tolerant 





Zak 


s e redundant instrumentation does more than that; 
Aura NOrmal operations, the logic circuitry is able to 
e leet the Dest possible signal using various multiplexing 
techniques. . 

A patie = tolerant control system using redundant instrument- 


on can be illustrated by the flowchart in Fig. 1.1. 


PRIMARY 
MEASUREMENTS 


ANALYZER Ono 





Multiple Signals Liocessmo ns ec cing 
from the Moss 
Redundant Instruments Reliable Signal 


A Control System Flowchart 


Considerable research has been performed in the area of the 
center block, the complex process of assuring that a most 
reliable signal is always available. On the other hand, very 
little work has been done to combine the advantages of 


Peeunaant instrumentation with the highly reliable techniques 





Mugi = 


on ulivi. In fact, since Dean Karnopp and Erich 
pemaer Tirst reperted their experimental findings for an analog 


N29) 


system in 1966, hardly any other reports have surfaced. 

The entire chapter 2 has been devoted to the errors and 
Mie rtalnties of primary instrumentation, so no further mention 
mis subject matter will be made here. Instead, the rest 
Of this chapter will be used to introduce to the reader the 
concept of fault-tolerance, a term many engineers have an 
idea of what the final output is, but barely have any notion 
or the manner in which the system performs its function. 
Mesually, the term "fault-tolerance" has only Deen- used in 
@emmection with digital systems for the last 5 to 10 years. 
Serer, the concept of fault-tolerance, or more explicitly, 
the term "redundancy", has been in the standard vocabulary 
Of most design engineers since the 1960's. 

mie LOcLe circuitry mentioned in the preceding paragraphs 
could be basically made up of simple passive elements like 
fm Or OR gates. They could be logic circuits that would 
Select the upper or lower value from a set of signals; or the 
Circuit could simply select the median from the same set of 
Anais. In any event, when one instrument does fail, the 
cane reading can be either high or low, or none at all, 
me ie LOStC circultry can take care of that by either 
Wesks:ng the physical fault from being transmitted further 


downstream, or in some pre-programmed fashion, acts to continue 





in SG 


to provide a reasonable output, although somewhat degraded. 
Mapeo Will discuss the actual multiplexing techniques in 
detail. 

Some electrical engineers share the viewpoint that the | 
presence of fault-tolerance features does not add any perform- 
ance advantages during normal (fault-free) operation. More- 
over, they state that fault-tolerance requires additional hard- 
‘ware that is redundant during normal operation and would be 
entirely superfluous in a completely fault-free logic machine. 

The author wishes to point out that in a fault-tolerant 
control system that uses redundant instrumentation, the fault- 
tolerance feature actually improves the overall quality of the 
various signals and improves the reliability of the entire 


system even during normal, fault-free operation. 


Be Reasons for Fault-tolerance 

What are some of the incentives for implementing 
fault-tolerance into a control system? The objective of 
minimizing downtime was mentioned earlier, but there are 
other advantages that have not been mentioned. 

In a thermal power system, if there is only one RTD at a 
critical temperature sensing point, or perhaps just one diaph- 
ragm at the pressure sensing point, then if the instrument 
malfunctions, the usual solution to the problem is a manually 
controlled maintenance action that results in the removal 


repair of the cause of the fault, The system is then 





— GR 


NAO S 5 IU l the next teult strikes. The purpose 
Bere colerance is to offer an alternate solution to the 
feng problem in which the detection of faults and the 
Recovery to normal operation are carried out as internal 
Mine rons Of the system itself. In this regard, fault- 
memerance can be considered as the survival attribute of the 
rc machine because its function is to return the system 
Boom error states back to certain specified behavior. 
iiitnoukb Tault=tolerance, a typical malfunction or 
mere usually occurs in the following sequence: The event 
Beeins with the observation of erratic behavior and a call 
Ane maintenance expert and ends with the resumption of 
Bermal operation N hours later, with N usually found 
somewhere in the range of 0.12 N4 10. If fault-tolerance 
MENO Incorporated into the control system, human particip- 
ation in recovery is eliminated, and N can be lowered to the 


I to 107° Pour. 


amne of 10 
Historically, fault-avoidance has been used as the 
alternative to fault-tolerance. Unlike fault-tolerance, 
fault-avoidance requires the physical components and their 
assembly techniques to be as nearly perfect (fault-free) 
as possible. In addition, shielding must be installed to 
QU all forms of external interference. The Apollo 


Space program was an excellent example of fault-avoidance. 


Bern single component was made to perfection; and the 





zone 


result, as the reader knows, was a flawless space flight in 
every launch. 
As one might expect, fault-avoidance has some drawbacks, 


en) 


and they are by no means minor. Finst not surphisingly 

to anyone, is that it is very expensive., The cost of obtain- 
ing nearly-perfect components in an instrument rises very 
rapidly after failure rates have been reduced to threshold 
values that are characteristic of the physical parameters and 
mamutacturing technology of the components. Second, since 

mae System will cease proper operation with the first failure 
or malfunction, manual—-maintenance personnel must stand by 
continuously with appropriate fault-—location and fault-removal 
BOS and methods. This requirement represents a major budget 
| Cor the life-cycle cost of the system. 

The acquisition cost of a fault-tolerant system is higher 
than that of a fault-avoidance system. This additional cost 
IO LO the extra effort required to introduce fault- 
tolerance during system design stage and by the cost of redun- 
dant hardware and software that implement fault detection and 
MOCOVery. 

However, the high initial cost could be more than comp- 
K J for by the lower life-cycle cost. The reduction in 
life-cycle cost is a result of the following reasons. First 
of all, lower cost components can now be used because higher 
failure rates can be accepted for individual components with- 


out degrading system reliability. Secondly, a sharp decrease 





2o 


in downtime will lead to a considerable lower life-cycle cost 
iis visuen operation. And finally, scheduled off-line 
meplacement OL rejected parts should cost much less than pro- 
viding a crew of continuously ready maintenance experts. 

Without redundancy and fault-tolerance, an unpredictable 
shutdown in a power generation and distribution plant may 
represent a tremendous loss in revenue. Another example with 
uu result is the electronic fund transfers, or the 
bel'ephone switching systems. Besides cost saving, however, 
there are other features of a fault-tolerant system that make 
2c highly desirable. Human lives could be endangered if a 
ie Occurs in some applications. Some of the examples are 
air traffic control, automatic control of a submarine in a 
Mion Maneuver, control of nuclear power plants and defense 
systems, and patient monitoring and life support systems in 
highly automated hospitals. 

Besa valoda group Of control systems that would 
benefit immensely from fault-tolerance consists of systems in 
environments that do not allow access for manual maintenance, 
Mas satellite in earth orbit; auclear reactor instrument- 
ation in a highly radioactive enclosure; unmanned underwater 
stations; and environment-monitoring stations in remote and 
hard-to-reach locations. 

And finally, there is a strong psychological incentive 


for implementing fault-tolerance in any control system. 





Sa: e 


When an operator knows that the failure of a system can 
Topar rdize a person's safety or economic well-being, or 
possibly the very first component failure will be fatal to 
the uninterrupted operation of the entire machine, the 
knowledge that fault-tolerance is being used is more than 
likely to considerably reduce his anxiety. 

The author wishes to clarify one point at this time. 
There are distinct differences between primary sensor reliabi- 
lity and computer (logic circuitry) reliability. Primary sen- 
sor reliability deals with the reliability of the instruments 
themselves. Obviously, each instrument has its own failure 
rate; some are more prone to failure than others. In addition, 
each instrument has its own range of uncertainties and errors, 
inherent to any particular type of sensor. On the other hand, 
fee circuitry reliability deals with the failure rates of 
aual circuit elements. The circuit elements, almost exclu- 
sively, are passive components like diodes, resistors, and 
OR gates. As compared to the instruments, these passive 
elements are highly reliable, at least partly due to their 
well-controlled environments both in manufacture and in use. 


More discussion on this subject can be found in chapter 4. 


OS Implementation of Fault-tolerance 


So far in this chapter, the discussion has been 
almost exclusively devoted to the following two areas: 


(1) The interaction between the logic circuitry and the 





=, 5 Dn 


physical instrumentation system, and (2) the incentives 
for implementing fault-tolerance. It is now time to 
describe the common methodology for actual implementation. 

Typically the control system is invariably designed 
mer perfect components, assuming fault-free conditions. 

Then, fault-tolerance is introduced. This sequence implies 

additional provisions must be made to add more hardware and 

perceware Clements. These redundant instruments and circuit 

elements will serve to provide the fault-nandling algorithms 
ema the spare parts needed for recovery. 

Fault-tolerance can be introduced into a control system 
through a systematic sequence of design activities like the 
following: 

(1) Reliability Requirements --- Reliability require- 
ments must be specified; in other words, a set of performance 
Speelfications must be defined. 

Fault-tolerance, in this case, is limited to the tole- 
rance of physical faults in each channel. A physical fault 
is an out-of-specification or otherwise undersirable change 
in the values of one or more primary parameters in the system. 
It is caused by a physical failure or degradation that affects 
a primary sensor and may make either a permanent or temporary 
change in the sensed values of the corresponding physical 
variable. 

Permanent physical faults are usually caused by irrever- 


See Changes in components, such as broken RTDs, open 





"Oo 


Somi-emmous, ruptured bellows, "bridging" between two leads, 
Bec. zyemporary Taults, on the other hand, are generally 

eeu CSRO external interferences of relatively short duration, 
typically in power supplies or in signal transmission. These 
meer rerences change the present values of certain measurements, 
do not cause irreversible damages to the components. 

Ao ra iquentaitative reliabilicty recuirenent nas been 
mes shed, the number of redundant channels needed can be 
Ame rmined. Each redundant primary instrument with its asso- 
Area branch of the logic circuitry constitutes a Me Jundant 
n]. From experimental results and other evidence, it 
pears likely that the triply redundant system is the optimal 
cC lice, 

(2) Fault-Detection Algorithms --- The detection function 
iS the starting point of most fault-tolerant implementations. 
This function usually leads to the addition of new components. 
n Ot” tault-detection techniques is governed by the 
emalli ty specification, making certain that all relevant 
Mme Classes are detectable, and that the probability of 
en derecetzron 1S adequate with respect to the reliability 
gOals. Both hardware and software techniques are applicable 
Mere. 

MIE aos mer noas tor meule detection can be summarized 
as follow: | 


(a) Initial testing, which takes place prior to 


x 





Zee 


Messe ana Serves tO identify faulty instrument 
Gs I rS COntalining imperfections introduced during 
the manufacturing or assembly process. >? 

(b) Concurrent (on-line) detection, which the 
auchor considers as the most Important method because 
after all, the underlying advantage of any automatic 
bel son is its seli-checking feature. It is 
Wii -nentged by means Of special hardware or software 
meen ODeraves concurrently with the regular programs 
es Sem... Concurrent detection is important 
pecalise 1 allows pecovery to be initiated before fault- 
caused errors can cause extensive disruption of programs 
or damage to the data. Hardware methods for concurrent 
detection have been used for quite some time, especially 
in the computer and aerospace industries. These methods 
include error-detection codes (chapter 5), duplication 
ai Comparison, disagreement detectors wich voters 
(chapters 3 & 4), and plant status and completion signals 
(chapter 5). 

(c) Scheduled (off-line) detection, which takes 
Aee on normal operation is temporarily interrupted. 
This method is quite similar to the initial testing 
except that now the testing is executed by the system 
itseir. (45) 


(d) Redundancy testing, which serves to verify that 





Pi aos obs OI protective redundancy are themselves 
Pere ree ana vakes place either concurrently or at 
Semeauled cone” 

(3) System Recovery Algorithms --- The recovery algorithm 
comprises all actions that are initiated by the arrival of a 
ieee Slenal during normal operation and are normally completed 
by the resumption of normal operation (more than likely in a 
degraded mode), by a deliberate shutdown of the system, or by 
== Lem failure. 

Poe emose iundamental difference between various recover: 
peeeorichims is wnether interaction with a numen maintenance 
Bor is or is not required as part of the recovery algorithm. 
Recovery algorithms that do not require human decision making 
Seenaucomatic; all other algorithms are manually controlled, 
osa they may contain extensive srosrammed sequences. 

immense COMpULCr and aerosogaece industries, most recovery 
EMO ricoms are fully automatic and require no human interven- 
MOT. nel: a certain processor fails, full recovery simply 
Ives with the replacement of the faulty processor witn a 
meee. However, in the thermal power industry, in the opinion 
Ene author, human interaction must play an important role 
meri cover, process, at least in the foreseeable future, 

e ECOV er aS been completed, the system can have 
RONE three status: full recovery, degraded recovery, 


and safe shutcown. 





Ad 


ERBE: cover, means the return of the system to a set of 
s illons that existed before the farit Occurred. In the 
case of a thermal power plant, this procedure usually begins 
iL a status light on the monitoring panel identifying one 
Amore malfunetions have occurred; plant is operating in a 
degraded mode, and it is now up to the human maintenance 
@eeravor to pinpoint the malfunctions and replace the damaged 
Meets. Recovery is concluded when damaged parts have been 
meplaced by spares. 

Nes radedirecovery means that the system is still operating, 
Aras a reduced capacity. In a triply redundant instrument- 
atıon system, an example of a degraded recovery is that two 
chamels could malfunction simultaneously, while the third 
mer is Still operating perfectly. The result is a piece 
dle ta that is not totally correct, but still within an 
ep table range. The system will remain in this mode until 
Bey instrument or component is replaced. 

re -shutdorm is the limiting case of degraded recovery. 
Ns carried out Only when the remaining computing capacity 
(if any) is below the minimum acceptable threshold. The 
bemectives of shutting dovn a power plant are two-folded: 

(1) to prevent damage to remaining plant components; and 
(2) to stop interaction with other plant system in a delib- 
w sc and orderly manner. 


M Sspecial case of hardware-controlled recovery is known 





era 


eccone More masking. In such systems, faults are 
masked by redundant hardware, and thus remain totally in- 
wii ble to the software further downstream. The masking 
function employs redundancy to assure that the effect of 
ESQ UL is completely contained within a system Ponce a 
As long as the redundancy is not exhausted, the fault is 
concealed within the module and no symptoms whatsoever appear 
wS Outputs. It is also known as a static redundancy 
we if viewed from the outside, separate detection and 
K ry functions are not identifiable. 

Masking is usually accomplished by hardware redundancy, 
fee. by the on O I rc ¿nec elements. The redundant 
eeements are assumed to be permanently Penne tea. and to 
meee Ssctavistically independently. They have the same failure 
rate and are instantaneously available to perform the masking 
Na luce with unity probability of success. One major 
Smeewoeeck Of static redundancy is that it must be introduced 
NS oOuUtset of the design phase. Total devotion must be 
Ben to fault-tolerance by the design engineers throughouc 
K I stage. It is for this reason, as mentioned 
METE, Ghat the initial cost of a control system featuring 


MEME =tolerance is considerably higher than that without 


the same feature. 





= 28 = 


J. The Author's Position on Type of Signals being Processed 


This is not a thesis on signal processing, however, 
the principle of multiplexing as applied here deals with the 
processing of signals from various redundant instrumentation. 
Therefore, the author feels that it is appropriate to briefly 
comment on the type of signals being considered here. 

All signals considered in this thesis are digital 16-bit 
parallel words. The 16-bit capacity includes a sign bit and 
an address bit. Moreover, these parallel words are results 
of distributed computing; in other words, the analog-to-digital 
Gemversion device is powered from an independent power source. 

ie Why Digital? 

Digital technology has indeed revolutionized 
the world of instrumentation. Reductions in cost of 
digital integrated circuits and the increase of chip 
complexity are rapidly making feasible the manufacturing 
of digital equipment at a small fraction of the cost for 
their analog counterparts. As a result, it is consider- 
ably easier and less expensive to find a digital system 
to suit one's need as compared to finding an analog 
system that performs the same function. 

Digital systems often capitalize on having a compat- 

ible data base. This is exemplified by a large and 

complex process-control system in whicn temperatures, 


Pressures, and flow rates are all converted into numbers. 





a ODOR A 


e UI SC input LS considered, its value ends up in 
piensen as a number. In chis form, it can be easily 
cesa smmlti plied, intecrated, or otherwise processed. 
2. Ja el Conversion 

tae HESE feature of this conversion approach 
e FLS Conversion occurs in parallel, with speed limited 
Sno Cne switching time of the comparators and gates. 
Ee eant Changes, Che Output code changes. Therefore, 
this 1S indeed the fastest approach to conversion. 

Only a few years ago, A/D conversion was done 
eich aa serial format, Dic by bit. Parallel conver- 
SONES not commonly practiced at the time because the 
number of elements needed in a parallel conversion 
miereases geometrically with resolution. However, with 
Pae avent Of LSI and VLSI technologies, it is now 
Bo eıiple ve have high resolution and fast speed at the 


No) 


same time. 
DI Distributed Computing 

D ecic cd compurtimnessimpliy means that the 
A/D conversion and related processing will be done right 
A INES ten source with an independent power supply. 
Bniszsteehnigque, when utilized in a redundant instrument- 
AOS y stem, accomplishes two objectives: first, it 
increases system reliability because a power failure 


anl o afteet that particular channel; and secondly, 





"56 


Doce mir yine digital data back to the data center, 

a considerable immunity to line-frequency (50-60-400 HZ) 

Pei upfanefsround-loop interference is achieved. 

meme tuno does nor intend to cover the subject of 

A/D conversion in any great detail here; if the reader 

is interested, however, reference (9) provides excellent 

r her readings in this area. 

From the general introduction in the preceding paragraphs, 
mers hoped that the reader has gained some knowledge of how 
faeeeult-tolerant system performs and why its implementation 
Mco rtant to a thermal power plant. In the next chapter, 
vebious kinds of typical power plant instruments, e.g. temp- 
Erature and pressure sensors, will be described, along with 
eMe uncertainties and errors peculiar to each type of instru- 


ment. 








ee 


CHAPTERTIT 


INSTRUMENTATION ERRORS AND UNCERTAINTIES 


A. tae Produce ts on 

1f an ino trunenc does not Seem to have maltunet= 
memed, then why should one worry about errors and uncer- 
Mes? Likewise, if an instrument appears to be as good 
Ine day iL came off the production line, why should the 
Measurements not be all accurate? 

ns Oo when an instrument becomes faulty as a result 
open connection, a mechanical failure, or a bridging 
K adjacent leads, to name only a few examples, the 
Measurement may become totally erroneous with a reading 
several magnitudes different from a normal reading. In this 
case, Has rument would simoly naye to be replaced at the 
erst ei. 

Thus, as one can see, an instrument can malfunction at 
Zr, zdependings on its Own failure rate; but in addition, 
ezen when it is operating under normal conditions, its 
winnie can stili be out-of-specifications simply due to 
Wii errors and uncertainties. The reader must realize, 
however, that each sensing device possesses unique charact- 
tes that make it especially desirable in a particular 
application. 

Poe cilsmenapeer, temperature and pressure sensors, the 


OSC important and commonly found instruments in a 





2 o 


mina! power plant, vill be explored. Their calibration 
Meee races, nolse figures, accuracy, and other errors will 
be examined. In particular, platinum resistance temperature 
detectors (RTDs) will be discussed as a specific case-in-depth 
to illustrate the origins and nature of some of tne instru- 
mentation errors. Reference (10) contains a comprehensive 
m ction of literature One Var louse aduUstrialwumermome cers . 
meetin chapter 4, the techniques of minimizing the effects 
Re se errors will be explained in detail. 

Maem Without dwelling upon che theories of probabilities 
Ome Statistics, one can assume that the probability for three 
different types of instruments (a triply redundant case) to 
generate similar errors (both in sign and magnitude) is very 
Le, it is here that redundancy demonstrates its most 
salient advantage. The use of redundant instrumentation 
Sa with the technique of averaging or voting will yield 
Mie most reliable and least noisy Signal at all times, as 


the reader will see in chapter 4. 


B. meslstance temperature Detectors 


INIA REMOS widely sased temperature sensing 
res are resistance thermometry and thermoelectric 
Me mometry. Resistance thermometry can be divided con- 
MEnmentliy into two basic groups: resistance temperature 
detectors (RTDs) and thermally sensitive resistors 


(thermistors). Thermoelectric thermometry will be discussed 





Piece. wemere woactcally electrical circuit elements formed 
of solid conductors (usually in wire form) that are charact- 
ig e post urvye coefficient of resistivity. The RIDs 

m al usage are of platinum, nickel, and copper. 

Mrs no question that platinum is one of the best 
Materials for a resistance temperature detector, nevertheless, 
MN ibDits Certain calibration drifts and errors during both 
testing and normal operations. A thorough evaluation was 
memeucced on the performance of several industrial platinum 
mecrmometers between 0° ana oe by the Oak Ridge National 
Woorfetory, and some of the findings are briefly summarized 
iene following PESANTI 

T. Insulation Resistance 

Considerati oN Or insulation resistance is 

Eweniticant because it could indicate that measurement 

sRrorns might be caused by shunting of the sensing 

ewememe aue to leakage of current to the sheath and pet- 

ween lead wires. In the experiment conducted by the 

Oak Ridge Laboratory, it was found that insulation 

Mesas tance varied widely tor similar type of thermometers, 

but from different manufacturers. But more importantly, 

eis also discovered that even for thermometers in 

the same group purchased from the same manufacturer, 

Msbouclee arrrerences or several decades were not 


uncommon. 





AS 


2. Thermal Emf's 

Pewecrtmencval results indicate that in order 
to reduce thermal emf's, parallel lengths of wires in 
Efemerermonmeter must have similar thermoelectric 
properties, anad thermal gradient between lead and 
points of lead attachment must be minimized. 
on GCabvonacion Drift Test 

A summary of the calibration drift test 


results is tabulated in TABLE 2.1. 


TABLE 2.1 
Manufacturer 

B C D 
Number of thermometers 
cested 2 4 5 
Number that failed 
immediately 1 1 O 
Number that failed within 
mOOO h 2 1 O 
Number that survived 
$000 h O 3 5 
Maximum differential 
drift in °C, after 6000 h = no 0.5 


Maximum absolute drift 
in °C after 6000 h = je 0.9 





= oe 


Me morse case, the absolute accuracy ot the 
thermometers changed approximately Dich Some thermo- 
Detercshac positive errors, while others developed 
a negative drift. 

4, ermal Cycling 

All thermometers survived 1000 cycles without 
we kage after they were cycled between 260°C and 
50°C. ln ipe Cempernasurmenlimi sS were changed Lo 
vele between 760° and 80°C at a maximum rate of BOG) ae 
one then omne tersS failed within 31 cycles. 
Sis ipaeee, Ot Cay Scale Derececs 

It is obvious from the preceding paragraphs 
enat platinum RID may cause certain temperature drift 
suine Service, and may even fall when subject to 
severe thermal cycling. Errors may also occur as a 
Mostro crystal defects Or fabrication imperfection. 
Ine troduction of such physical defects into a 
crystalline material like platinum, will cause an 
Imerease in its electrical resistivity and therefore 


an error on its usss s 


Thermistors 


Thermistors are electrical circuit elements formed 


word semiconducting materials that are characterized by 


a high negative coefficient of resistivity. At any fixed 


temperature, a thermistor acts exactly as any ohmic con- 








we ple Otcaleuaecringstor resistance variations are from 
50,000 @ at 38°C to 200 at 260%, ‘19) 

Some of the semiconductor materials that are commonly 
meed to manufacture thermistors are carbon, germanium, and 
Silicon. The author will concentrate on the application 
of thermistors to temperatures below 100 K or ec, 

Mere are two important reasons for this selection, First, 
materials and methods of thermometry which are well developed 
mor higher temperatures often fail at lower temperatures. 
Second, problems associated with the application of ther- 


14 
mistors become more serious as the temperature is OS ) 


l. Temperature Dependence 
When carbon resistance thermometers are 

monitored at a fixed low temperature, their resistance 

LS observed to drift with time. As the temperature is 
lowered, the drift becomes more serious. If one requires 
a stable carbon resistance thermometer, he must sacrifice 
temperature resolution. Part of this loss in resolution 
can be restored, however, by using a resistance bridge 


bebable of a greater resolution. +9»*8) 


2h Power Dissipation 

The measurement of resistance requires power 
dissipation in the thermometer. Thus, power dissipation 
must be kept small to avoid excessive measurement error. 


It has been found that a power dissipation as little as 














D. 


e y 


=l P n Carbon resistor at 0.04 K caused about 


a one percent error in a t/t, $14) 


Sh Soin eating 

Woren problemn cher is Not so easily dercected 
is power dissipation resulting from rf voltages induced 
in the leads by commerical radio transmitters. This 
effect is known as self-heating and is e problem common 
GDO Carbon end germanium thermistors. Error caused 
BR le spurious power dissipation becomes much more 
Serious as che temperature is reduced. In areas exposed 
portarse pz tields, the electronics must be placed in 
a shielded enclosure; otherwise, tne placement of a low 
K S jO Rin une electrical lead near the resistance 
Frermemeter may be sufficient. An efficient and ade- 
quate heat sink also appears to be an effective method 


A 1 7 
tO minimize such a! ) 


Bene Meral Thermocouples 


teo aper eC CEREO COUPLE would be one that 


K us an emf Signal that 1S uniquely related to the temp- 


Ie or the hot junction and is unaffected by time or any 


Seer 2accor. Although noble metals like platinum are 


INS Tor to most, no materials of construction are completely 


Salte in this regard. Mechanical failure is a major 


K Cine factor to instrument malfunction, but in the 





= Sere 


Seco tee OL emacs, Thermocouple deterioration is usually caused 
i sof composition. yhich influence the emf developed 
ever the temperature gradient to which the couple is 
Bipjected, ‘2°? 

A highly corrosive environment appears to be the major 
ee for compositional changes. Most environments above 
1300°C are ince ly hostile; in addition tO vapor transport 
processes associated with the formation of volatile oxides, 
Aca reactions can also occur between the thermocouple 
meres and the insulating materials with which they are in 
cemtact, 

1. Contamination 

Mechanical fallures of platinum thermocouples 

are sometimes caused by contamination during fabri- 

S2t10n.) @he embrittlement, which sometimes occurs 

Men platina cGhermocouples are heated in contact with 

alumina insulators under reducing conditions at temp- 

EPatures above LOO C, is usually associated with 

MIO ccemoc On Silicious impurities in the refractory. 

u Oe Oor Teaction results in the formation of low 

MemeLne point alloys, and the thermocouple usually 

fails abruptly before a serious change in thermal emf 


(18) 


mets occurred. Sacos impurities are usually 


Mer roduced during the wire drawing process of platinum. 





= 36 -— 


ar teenie Drift 
Tıerzmoceileetrie stapLııirwpecomes an important 

jS Oo when an instrument Operates continuously for 
thousands of hours. Experimental results indicate that 
bmermal drift is related to compositional changes 
erase cae drift has been LOoungd= Go be a direct result 
of change in the chemical composition or metallurgical 
muructure of the thermocouple materials after exposing 
to a thermal ea 

Omne Or rne Operating conditions that affect the 
Menne Oi thermoelectric drift are as follow: 
(a) temperature level, (b) time, (c) temperature gradient, 
(d) environmental gas, (e) pressure level, (f) thermal 


eyeling, and (g) nuclear cee” 


DI lle /ibereRursetEerrors duegtont0atalytio Surface Burning 
ena metal Suncrmeeeupsc is exposed to various 
aneompletely—burned gases that exist in some engine 
exhaust gases, it is entirely possible for catalytic 
an js Oso Curr on the surface of the thermocouple. 
is bpürning will raise the temperature of the ther- 
Meecubpiie to a value that is higher than that of the 
surrounding gas medium, (20.21) 
INserrer vemclinimace catalytic reaction, design 


dui -incers have recommended coating the temperature 


probe with a non-catalytic material. Some of these 





= 40 — 


hemM@eeoavcin cele coatings include pocassium-chloride and 


oxidized sim, ‘22 


Variable Resistance Pressure Transducers 


la bocendlonetrio Pressure sicansaucers 
Pe pOpCheLOMecumme pressure transducer is a 

Sewiece consists Of three main components: the force 
PERE StOr, Che sliding contact wiper, and the resist- 
ance wire winding. The pressure to be measured is 
Medar tae rorce collector which, through a linkage 
moc, Moves a Sliding contact across the electrical 
Be-SiSstanee wire windines, thus producing a voltage 
wopo cr ronal Go the pressure. A diagram that illustrates 
meme basic operating principles of such transducer is 
menan appendix I For more detailed descriptions 
and specifications of various commercially available 
pressure transducers, the AGARD publication "Wind 
Tunnel Pressure Measuring Techniques" (23) and the 
ISA "Transducer Compendium" (24) may be consulted. 

er oj i lO t (T electrical noise are the two most 
Beevere problem areas associated with the use of 
enc onecie transducers, especially those employing 
Mmeeo Widnes resistance elements. As the wiper moves 
dewoss tLe windings, a step resistance change is 


eS weeauca wae che wiper disconnects with one winding or 





lesse acc) another, the amplitude or this step 
change, and therefore the resolution, depends mainly 
meen che geometry of the wire windings and Wiper. A 
jJ s Ju ue Of resolution for most potentiometric 
transducers is 0.2 percent of full scale. (23,26) 
Electrical noise is generated due to variation in 
contact resistance as the wiper travels over the 
peers uence element. Contact pressure fluctuations and 
bpamuLcle Contamination at the wiper=wire contact are 
evel tne Causes for these variations. This noise 
S r Lion Lends Co increase wich the life of the 
I C punent Decause of wear and misalignment of the 
weper ene track. Noise spikes may also be caused by 
a n (L or sich tend CO lift the wiper from the 
MSP e element. mIn addition, "any linkage required 
Mene transducing system will cause the instrument to 
bel a aS a UO tO vibration. Recent transducer 
1 S SC ne method of oil damping on the linkages 
me estic elements to reduce the narmful effects 
or Vibration. . 
ieee |, che spoxenesrometric transducers should 
Men eain aheas Of low acceleration primarily for the 


measurement OL static pressures. 





F. 


A 


es Strain-Gage Pressure Transducers 


A strain-gage pressure transducer is an instru- 
ment in which a pressure change caused by the strain in 
a strain gage is converted into a change in resistance. 
More details on this type of transducers and their 
electrical schematic diagrams can be found in appendix I. 

Full-scale pressure ranges from O to 0.1 psi to 
OmtowtOO,000 psi are provided from various types of 
strain-gage transducers. In some models, static error 
bands as low as 0.1 percent of full scale can be 
achieved. If temperature compensation technique is used, 
transducers with temperature sensitivities as low as 
0.25 percent of full scale can be fabricated. Most 
strain-gage transducers are eat sensitive to 
acceleration and vibration. Moreover, in pressure ranges 
Bar TO psi, errors of 0.5 percent of full scale per 


g are not eara?) 


Diaphragm-Type Variable Reluctance Transducers 


A variable reluctance pressure transducer commonly 


used in the power industry employs a magnetic diaphragm as 


the sensing element, supported between two inductance. core 


assemblies. The diaphragm deflects when a differential 


pressure is applied to the pressure ports, thus changing 


the magnetic flux. A detailed diagram of such transducer 





us ovi dn apoendix I. 

Mco eme or advantasestotrtterod"boy Chis type of 
Wes ducer is its sensitivity and acceleration capabilities. 
Pressure sensitivities as high as one volt per psi are 
Al able, and pressures down to 0,00003 psi may be measured. 
Ida ttion, due to the extremely low seismic mass of this 


Meme; Cevice, it is carable of withstanding high levels 


ce) 


DO 


Ma cceleration.. 
A major disacvantase of this transducer is its sus- 

Mo liu tOo particle contamination. If the fluid 

contains particles, they may easily become lodged in the 

small air gap (~ 0.001 in) between the core and the 

G r. Consecuently, the performance of the instrument 

M aded either by mechanical or magnetic interference. 


wond disadvantage of using this type of inductive 


transducer is that AC excitaticn must be used. 


G. Mis-zoceileetrie Pressure Transducers 

lede ls denned as an electrical polar- 
On produced by mechanical strain in crystals belong to 
Meme) Classes, the polarization being proportional to the 
Bereain and its sign related. to the direction of the strain. 
Me piezoelectric element is stressed mechanically, its 
(25) 


~en ons change and an electric charge is generated. 


u r po of sensor does not require external electrical 





A ia 


Ber eeemooes sue variable resistance or the variable 

Pemueecemee transaucer. <A variety of piezoelectric materials 

pepemuced, with quartz, barium titanate, lead zirconate tit- 

deine, and ceramic elements being some of the more common 

ces. 25) 
lezoelectric elements have an inherent high internal 

I TStance eo > LO w ohms) and a low capacitance (5 to 

500 pF); thus, a slight leakage resistance path across the 

element electrodes or across the electrical connector pins 

K ° erratic operation and limit the low frequency 

Meeponse of the sensor. Therefore, it is important to 

meni Protect the piezoelectric element and all cormnectors 

w Moisture or other contaminants that misht create con- 


duccion paths. ‘29? 


Me. 5 LO Type Liguid Densitometer 

Tee e loas iO Lype lionuiagqa density measuring 
een, the vibrating tuning fork is the basic principle of 
Cus On, The density device uses a hollow vibrator element, 
Atar to a tuning fork, through which the measured liquid 
meee. As the density of the measured liquid changes, the 
mass and the resonant frequency also change. In fact, the 
Wééwéhcy is inversely proportional to the square root of the 
n (O = K//g . An electrostatic capacitive pickup 
ode connected to an amplifier converts the vibrator 


displacement to an alternating voltage output, which corres- 








ei 


memceesco che density of the liquid. 

Mercal” Cetiy” study nas been conducted OM ules va ora ci On 
foe 1iduid densitometer, thus the origins and nature of 
Seeors associated with this type of densitometry are not 
Semmoniy known. One can, however, obtain an idea of the 


Capabilities of such an instrument by the following speci- 


Be dons:' 2°) 
Measuring range: O Sion g/cm” 
Span: 0.05 to 0.5g/cm° 
Repeatability: 1% of span 
Wiocarity: = 0.5% of span 
Working Pressure: 20 kg/cm? G or less 


Working Temperature: -10 to 100°C 


T Concluding Remarks 

mE NSC Rap Cer CNe author has not attempted to 
cover any particular instrument in great detail; in fact, 
that would be ona e sScopemo Pri E UresisSs; If more 
detailed descriptions are desired, the reader is advised to 
consult appendix I and some of the references listed. 

If the reader has learned nothing else in this chapter, 
the author hopes that he is now at least more aware of the 
K rL different instruments behave so differently under 
a same environmental conditions. One instrument may 


yield a higher than normal reading, whereas a second one may 


produce an unusually low measurement; yet a third sensor 





simply fall completely. 
Mena pers 3 ana 4, the autmeor wall discuss the prin- 
Giples and advantages of averaging, mediating, and voting, 


K s Icon control system using redundant instrumentation. 





ao n 


CELA EL 


PROBABICISTETOTCOCGICS 


A. ie POdUCTLON 

Feeecotiistic logics entail the Study of error in 
MESS, or in the physical implementation of logics. Error 
[meevilewed, according to J. von Neumann, not as an extraneous 
Semboalrecting accident, but as an essential part of the 


130) Neem PUR” study of 


weess under consideration. 
MeempeolLiistic logics has a far greater influence; its 

wipgementation can be considered as the predecessor of all 
multiplexing techniques (a fundamental concept for voting) 


and coding methodologies (encoder and decoder), as the reader 


fee see more clearly in the paragraphs to follow. 


Be Logics and Automata 

| A. M, During“) in 1987 ana W. S. MeCulloen >? 
ISS suegested that probabilistic logics can be best 
studied in terms of automata. An automaton, as defined 
PON Neumann, is essentially a "black box" with a finite 
Mer of inputs and a finite number of outputs. Each 
Pomc and each output is capable of exactly two states, to 
bewidestonated as the "stimulated" state and the "unstimul- 
pea’ State, respectively. 


Mer internal functioning of such a "black box" is 


ui Jent to a set of specifications determining which 





= 43 = 


Sot wlll De stimulated in response to stimulation of 
Si) Of inputs. The definition just mentioned is 
precisely the concept that an averager or a voting cir- 
cuitry (two of the most commonly used multiplexing tech- 
niques) is based upon. In addition, the theory of auto- 
mata can also be applied to the tasks of encoding and 
sic in which a specific number of inputs can be con- 
tea into either fewer, same, or greater number of out- 
mes, depending upon the specifications of a particular 
Week box". Therefore, an understanding of probabilistic 
Bes is useful if one wishes to learn more about the 
Beer Zending quest of higher reliability in a control 


system. 


Ch ine Technique of Multiplexing 
l Ellen u Kon son u pore bundled together, 


an automaton can now be represented like that in Fig. 3.1. 
messages willl be carried simultaneously on a bundle of 
N lines (N being a large integer) instead of just a single 
m Te strand, Instead of requiring that all or none 
Ne Lines Of the bundle be stimulated, a certain critical 
(or fiduciary) level À is set: O < A < Z. The stimulation 
of > (1- A) N lines of a bundle is interpreted as a positive 
Fun Or the bundle. The stimulation of <= AN lines is 


red as a negative state. Any other number of stimulated 





AS = 


aus interpreted as a malfunction. By constructing the 
iieemacton appropriately, it can be shown that the number 
il es deviatine from the “correctly functioning" 
Wworities of their bundles may be kept at or below the 
critical level AN (with arbitrarily high probability). 

J. von Neumann called such a system of construction "multi- 


eng, (30) 


Each group == represents 


a bundle of N lines. 


Fig. 3.1 Automaton as A Black Box 


Mier technique of multiplexing requires that the comp- 
lete system must be organized in such a manner, that a 
malfunction of the entire automaton cannot be caused by the 
Memrunctioning of a Single component, or of a small number 
Smmeemoonents, but only by the malfunctioning of a large 
number of them. As the reader may observe, the probability of 


Seem occurrence can be made arbitrarily small provided the 








Some 


moet sor lines in each bundle is made sufficiently large. 


DE Von Neumann's Majority Organ 
d hem Sic Executive Organ 


WpieWepiterion tiara control system fails only 
acne majority of the inputs malfunction led to the 
ention of the majority organ by von Neumann in 1952. 
DE zmajority organ will be able to handle. Bundle of 
maples and outputs as well as single lines. For the 
Fake Of Simplicity, however, the majority organ will be 
modelled as a black box with three single line inputs 


mo. and ec of similar characteristics, as shown in 


mee. 3.2. 
m(a,b,c) = ab + ac + bc = (a+b) (a+c) (b+c) Corea) 
ine II Ori by Organ 
a 
b m are) 
C 


ELO e 


Here m(a,b,c) represents the majority of the input signals 
a, b, and c; ab denotes a and b, whereas a+b defines a 


sine the majority organ, it is clear that if any 





R es 


two of the three inputs are stimulated, the output 
Tie be szrimulated, Similarly, if any two of the inputs 
are not stimulated, the mechanism will not stimulate 
any oubpulsat all. 
Thus, it appears that the majority organ can also 
be called the basic executive organ because it executes 
the desired basic operations on the bufdles. After the 
Sccupton. however, the degradation caused by the 
xecutive organ must be erased; moreover, the stimulation 
leveltot the inputs nas to be restored. These two require- 
ments necessitate the creation of a second organ --- the 
BESLCOring organ. 
> The Restoring Organ 
a, Construction 
Eee  vormasorcean can be constructed with 
Fill u lite steana in fact, the ordinary major- 
ity organ already performs this task in a crude way. 
ss considers the simple case of having three 
nale at the input like that shown in Fig. 3.2, 
it should be obvious to the reader that the major- 
ity Be. a single incoming impulse as 
well as a single incoming non-impulse. In other 
vore amplimtes the presence as well as the 
Zoe mer sorzchezineoming impulses. 


B mon zeornrimuing any further, one note of 





oe 


inportcance Chat should be emphasized here is the 
HOMO nc order Orap Cne theories of 
probability and statistics to the majority organ 
concepte in various app ications, all inputs must 
Beuscoameldered as stacistically independent. 

What are the advantages of multiplexing? As 
mentioned earlier, the most desirable feature of 
a MUbtlLplexcd system 1S 91lts ablility to control 
errors, 11C can be Shown by Statistical analysis 
chac boy using larceeenough bundles of lines (N 
being the size of the bundle), any desired degree 
Sa Cua Cane obtained with a multiplexed 
automaton. Of course, economics and implement- 
Aauomsdırrieulties may dictate the largest num- 
Oc tnat N can take on: 

b. Numerical Evaluation 

Doeszche maorit organ really perform 
Pas of a restoring organ? The following 
<eo lation will attempt to prove just that. 

T£ chere are N incoming lines and N of 
Coe e oi mulated, then the probability of any 
majority organ being stimulated is 

ca anni. (8.2) 
Provided N is large, approximately e N outputs 


Je 
Wiebe seimulated. A curve of & against of 





Meee? = 


Lea LA Hig. dad. 


Numerical Evaluation of 


the Majority Organ 





tie -eunve intensecus sume diagonal a. Moac 
bip esatto S O Li, ma. For 0 < of < %, the 
curve indicates 0 < ai LA E Le 
the plot shows that XA < & < 1. In fact, suc- 
cessive iteration of this process converges SA 


to the asymptote at O if the original «x < % and 


to tne asymptote at 1 if the initial < > %. This 
forces Foe Process Of restoration for a digital 


Scie uOmOon Mis scemicanrer to either O or 1, to which 


ug 





Sie 


i u src ser originally. Thus it is shown that 
Ceea Oriy Orcan does possess the desired 


amenace terlstlies of a restoring element. 


E. temerity Organ Operations in a Digital System 


Poesias Mao Paynter of M.-I. Is went one 


Step further to develop the AND and OR logic elements in 


(33) 


eee detail. Innuedo ital or Dinary LOS Lo a NT 


doni yv take on the value of either O or 1. As in set 
theory, one can represent the AND operator with the inter- 
section symbol A , and the OR operator with the union 
esi v . 634) 


If there are two independent variables X, and X 


1 o) then 


‘ the operations of union and intersection may be represented 


in tne functional matrix form as shown in Fig. 3.4, 


Operations of Union & Intersection 





PIZ o4 





Mi D" 


Timer ccader mignu mOtice the Similarity between the 
above matrix and a conventional truth table. In fact, if 
Me Symbols T (truth) and F (falsity) are substituted for 
mame O, respectively, a truth table would have been con- 
suc Ced. 

meric inputs are S-bit binary words, the operations 
Wie and intersection produce some fairly interesting 


Wists. For example, if X, = 011 (3 in base 10) and 


1 


X, = moo (4 in base 10), then the operations of v and A 


ue represented in Fig. 3.5. 


X, V X, X, A X 


Ps 
Il 
O 


to 


Daron e Intersection of a Binary word 


ES 


I r ui 1n Eig. 3.5 indicate that the operation of 
MOT produces the larger of ene two 3-bit words, whereas the 
Seer actOrn Of intersection yields the smaller of the two words. 
concept will be developed further when continuum logic ís 


discussed. 





Se 


Fa Multi-valued Logic 


Sie wwascomeelvye a Spectrum Of multi-valued or 
n-valued logics with binary and continuum logics occupying 


Me ac seme positions. This com@ept was first introduced 


Me, Reichenbach 99? 


(36) 


in 1932, then evaluated further by 
Pic. Rosenbloom io 50 Frans Nor until 1960; 

M er, that the idea of multi-valued logies was linked to 
w dy of control systems by H. M. Paynter. 

iim two valued logic, absolute falsity is designated by 
value O, whereas absolute truth is assigned the value of 
is line of continuum logic, any other values tnat 
me eeen O and 1 may be interpreted as "partial truth" 
bei posed by Paynter., In a four valued logic, for example, 
NN Cut values might be viewed as "Truth", "plausibility", 
inte usibility", and "falsity". 


(37) 


Wéé.cXsystem proposed by E. L. Prost, L iere pom 
Brauch values which may be denoted by 1,2,3,..., (n-1), and 
me operation of the intersection A can be defined by 
n metrix shown in Fig. 3.6. 

Mito cit? oi Propositions for the case of multi-valued 


Meemes is known as Post algebra, as opposed to the Boolean 


Dra for the two valued case. 





Mo 

















1 
X; IN X, 1 
ee 
lalola... lo 
i VAR 
Me el A Post Logics 
> | 











Flo pa no 


G. Analogy Among Binary, Multi-valued, and Continuous Logics 


Ear logic can be demmed daS discrete logic, one 
that consists of only O's and 1's. A three-valued logic is 
composed of O's, 4's, and i's. On the other hand, an analog 
NAO continuous logic can take on infinitely many values 
Meee 0 andl. Fig. 3.7 shows undeniable similarities 


among binary, three-valued, and continuous logics. ‘38) 





2 58 = 


Binary 





3-valued 


Continuous 





Fig. 3.7 Similaries Among Different Logics 





T o 


Binary 


3-valued 





L. s x SS 5 
SY 


BIZI OAD 


eea omm llaries Among Different Logics 


E 





= Go = 


An analog analogy of the majority organ as first pro- 
K Ooy Payncer will be presented later in this 


Chapter. 


AS From Digital to Analog via Multi-valued Post Logics 


Dice ure coneept Of mualtiplexins and the prin 
meee Of the majority organ were first introduced by von 
Neumann, a great deal of contributions has been made by 
others in the area of reliability of binary system con- 
posed by subsystems interconnected in various ways by 
Ne rent Kinds of restoring elements. However, primary 
ms from many instrumentation, control, and communi- 
MON systems are still in a continuous or analog form. 
essere that much of the work dealing with redundant 
bieco! systems can be carried over to analog systems, but 
K que characteristics of a continuous analog signal 
necessitate a separate study. 

Unlike the simplicity of a digital system with its 
S Of O's and i's, or the multi-valued system with 
M nn te set of values, an analog signal is much more 
wex with its infinitely many forms and values. It 
was Paynter who first formulated an analogy between digital 
L. ITT elements and the upper and lower selectors used 


in an analog system. 





r 


E Continuum Logic 

In the world of digital O's and i's, von Neumann 
used the AND and OR organs as the two building blocks for 
Misma jority organ. Similarly, H. M. Paynter uses the 
wen and lower selectors to construct his median-taking 


(33) 


element for an analog system. Paynter defines the 
union operator V as the upper selector: 

K (k) = AAE TTR) | (SO) 
Ene intersection A as the lower selector: 

A X(k) = X(k ..) (3.4) 
where { X(k)} is defined as an aggregate of classes such 
that x | °K =, eee ono the upper and 
Men selectors in symbols. 

o represents a group ot Time—varying functions, 
Wiegeo loving will hold true: 

x= x(t) = {x,(t)|k= 1,2,3,...,n] (3.5) 

the upper and lower selector operators are now 
performed on a set of signals as shown in Fig. 3.9, 

V {X(t)} will represene tilceemcamcsu Of che x. at time 
t, whereas Á {x(t)} will depict the least. 


JR Sm rations Oof the Harie rran in an Analog System 


As suggested in section D of this chapter, the 


Es; organ can be represented in the following Boolean 


se onshinps; (38) 





ee 


M (X,,X2,X3) = (X,AX,) V (X,AX¿) V (X,AX,) 


= (X, V X.) A (XV X.) IN (XK. V X.) 


i symeols, these relationships are modelled in the 


@emricuractions shown in Fig. 3.10. 


Selection as a Process 


Upper ciecetor 










n y(t) = N Xy (t) 
INPUT 
SIGNALS 
Lower] Sto 
y= A AO 
INPUT 
SIGNALS 





Gee 


Operations of the Upper and Lower Selectors 





Saber Sas, 


Tr X (t), X(t), and Xa (t) represent three similar 
sinusoidal signals but saturated with different noise and 
distortion like that shown in Fig. 3.11, then M (X, ,X,,X,) 
actually takes on the median value at any time LA Saca 
the same symbols as shown in Fig. 3.11, y represents a 
Semeinuous median Ss ce 

In chapter 4, averaging and voting, the two multi- 


plexing techniques that are most widely used, will be 


discussed in detail. 


OT°S *3TA 





O41 poztTezsues əq usco 





wo220qQ WOLF PUOD9S d097. UOIJI PUO99S 





393181 | IS9TTeus | 


sated Aq 23S9aTTRuUsS sated Aq }səgZaeĽenT 


SN A A 


s10yet1asado Tena 


ue3ıo A4TaofeN əua JO VUTTTSPON auf 





2565 > 


Selection of Continuous Median Signal 


Special Case of Three Signals 





PIS. 3.11 





CHAPTER IV 


AVERAGING, MEDIATING, AND OTHER VOTING SYSTEMS 


D, e for Redundancy 


weon Crol System needs to be monitored on a con- 
tinuous basis; but if the instruments that monitor the 
w performance are themselves not completely reliable, 
mec ie system reliability is jeopardized. The control 
Lem must act on the basis of signals transmitted from 
mmemmcasuring instruments. If, however, these signals are 
Berry or inaccurate, then the system can no longer achieve 
email or even safe operation. 

ae importance Orsregundapr- instruments in a control 
system cannot be overemphasized. As already mentioned in 
Beer 1, if Only one instrument is used to monitor a 
s] parameter, the failure of that instrument a 
rus lead to catastrophe. 

Obviously, if a second instrument is installed to 
Mor The same parameter, the probability of system 
Bere is considerably decreased. For example, if an 
averager is used to process the signals from two redun- 
Aia struments, the output is clearly more reliable than 
aS put from a single sensor. The difficulty arises, 
Memwever, wnen the two transducer signals are vastly different 


ceca Other. Here the dilemma leads to the following 


G@i@esetOn: Which signal should one choose? In addition, 





MEI: > 


enevhien the faulty instrument is identified, a doubly 
Wed cane system does not allow for hot-repair. 

Here, the advantages of a triply redundant instru- 
Memection system become highly significant. In the 
wen gue of averaging, with one signal going astray, the 
ems, is only slightly in error, In the method of voting, 
er, as long as only one signal is erroneous, the out- 
wr emains correct. Furthermore, even when two signals 
e Tailed, but if one failed high while a second one 
Mea low, the output still maintained a correct value. 
~ mally, in view of the tremendous economic penalty for 
@emiicime, the fact that voting allows for hot-repair of a 
Ry instrument makes it especially attractive for a 
thermal power system. 

Mie” resder will learn more about a triply redundant 


ISE rumentation system in the paragraphs to follow. 


De ans ti1on from Digital to Analog to Digital 


John von Neumann's majority organ for a binary 
queen was first introduced in chapter 3. Ina binary 
n, as already illustrated in the last chapter, the 
meme and Output signals can be easily represented by 
memes Of O's and 1's. The majority-vote logic element 
can be constructed with a combination of two basic 
elements --- AND and OR gates. In fact, it is a relatively 


straightforward task to demonstrate the operations of the 





zus 


Decke y Organ in a binary system, as already done in chapter 
3 for a simple case. 

semneemene majondsby-=-vote logic was first introduced by 
von Neumann in his series of lectures at Caltech (California 


(30) a tremendous amount of 


meeeicuce of Technology) in 1952, 
meres, both theoretical and experimental, has been conducted 
Ne 1960's and 1970's to evaluate the reliability of 
digital systems using redundancy. It was in 1958, only 6 
MS after von Neumann presented his majority logic concept, 
merece formulated an analogy between digital restoring 
elements and the upper and lower selectors used in an analog 


(33) ASMENET Onc dE ber S Lhe unique character- 


system. 
istics of analog signals from most instrumentation make it 
Meeesscary to conduct a separate study to analyze the appli- 
eee Of mediation to an analog system. The experimental 
Berrzeonducted by Karnopp and Bender in 1966 verified the 
advantages that one would gain in the utilization of averaging 
and mediation in an analog a E 
A symposium on digital redundancy in 1962 may very well 
Mer started the transition from analog to digital with full 
ded In February, 1962, a two day symposium was held in 
frie ton, D.C. on Redundancy Techniques for Computing 


ems °°? 


mn i ch a bObkalwon more than 20 papers were 
presented by verious design engineers and mathematiclans. 


IN llection of papers was fabulous; it represented the 





Meta mer: cena dedication of numerous distinguished people. 
Wath the advent of digital to louy im tie TAS, 

emeetcal redundancy using the voting technique began to be 

mena tm various applications. The idea of a voting cir- 

uns ry is not new, but its implementation in the industries 

w definitely been an area full of innovations. During 

G o L few years in particular» industrial implementations 

F qancy are becoming more and more common everyday. 

Pome some of the more prominent examples are the Space 

uu Tc program, the strapdown redundant inertial instruments 


(40) 


fem irilicary ballistic missiles, anemunc Bell System 


Mes urónic Switching Systems (ess), 642? 


fi facto reports 
Mes area have appeared on a regular basis in journals 
Suchh as the IEEE Proceedings, AIAA Guidance and Control 


Semeeerence Transactions, Electronics, etc. 


Ge Averaging Multiplexing Technique 


L Immoduesren 

Tnezaverzeiımesmecsbecken De considered as 
one of the oldest yet extremely useful techniques to 
improve the reliability of a signal or data. One is 
familiar with the situation in which a photographer 
makes two or three spot readings with his light meter, 
men uses the average of the readings to set the 
aperture and shutter speed on his camera. 


A straightforward averaging technique involves 





a Oe 


Samo ly tekine the arithmetic mean of a series of readings; 
Pe unier words, Che weight factor is equal for all channels. 
Ms operation, performed by a device to be called an 
averager, reduces the failure rate of the measuring system 
according to o otal number Of Sensors. However, 
Kasi C Or error in any one of the inputs still affects 
mee waveragcing Output. If one knows a priori that a 
certain channel is more reliable than others, then a 
envier weight factor can be assigned to that channel, 
thus increasing the overall rciliabinano (9 
An even more elaborate "average" method is also 
wal able as a multiplexing technique. Here the word 
"average" is in parenthesis because this method resembles 
Mo tine tCechnigue more than the Ordinary averaging 
Fu Od. In this methodology, weight factors for each 
enannel are continuously changing based on cross-channel 


(43) 


differences among the several channels. More on this 


method later in this chapter. 
Er Hume tional Block Diagram 

Atypical multiplexed system can be represented 
by means of a block diagram like that shown in Fig. 4.1. 
ferme tne actual multiplexing technique can be averaging, 
meee—vtaking, or something more complex. The physical 
variable can be temperature, pressure, or any other 


engineering parameter. The noise at each channel may 


u 





My) = 















1 


INSTRUMENT & 
TRANSMISSION 
ELEMENTS 





CHANNEL 


CHANNEL 2 


INSTRUMENT & 
TRANSMISSION 
ELEMENTS 









PHYSICAL 
VARIABLE 


MULTIPLEXER 
OUTPUT 


INSTRUMENT & 
TRANSMISSION 
ELEMENTS 


Pio, 4.1) 2ypical plexed System 


«A 
/ 


, 


OUTPUT 


Fig. 4.2 A Linear Vote-taker 





rr 1s 


CMS eE LOllowing types: transmitted noise, in- 
Ponen or induced noise. The block diagram 
espr resents a triply redundant case. 


a Fue si s Of Operations 


An averager which takes a linear combination of 
Mes inputs to form its output is show in Fis. 4.0, 642) 
mesc apaın, a triply redundant case is presented here; 
Obviously, one may extend the technique for higher order 
aman U systems. Here the three input signals are 

Pr mmed to be identical, bút with different noise levels 
sperimposed on them, As mentioned earlier, if the 
zent factors, 24) Bos and aa all have the value of 
1/3, then the output simply will be the aritnmetic mean 


ate input signals. If we designate the output as 


Xout? hen the output of the averager is given by the 
Relation: 
z 
1 
‘out = 3 = Ay 


Peel Can be generalized to any number of signals. 

One of the limitations of a straightforward averaging 
Dechod is that a number of consistently unreliable channels 
m degrade the quality of the output. This limitation 
meme "Overcome, Newever, if the reliable inputs are 
feel) nheavier weignt factors and the unreliable inputs are 
MA Ter werent factors. Clearly, the reliability 


sueca” tallormade system must be determined on an 





298 


individual basis. 
4. Fei p ii oa Calculations 

Kasse ave FIC mebtaca, time output riil pe 
somewhat faulty if any one or more of the inputs is 
Mercy. It is clear that the probability of a faulty 
usss l l higher than the probability of failure at 
bei individual channel, This shows that if tne control 
sem requires that the output must always be exactly 
filiere C unen the averaging method may not be the 
Mine le no Lecce que to ivseniontrallure probability. 
mea e SS one must keep in mind that the averager 
output signal will noc deviace as much as a single 
aenal. Detailed reliability calculations and analysis 
for the averager will be performed in section F, along 


meme iii ose ol une voting element for case of comparison. 


SA Ep Sine nt al Mente ao 
a. Stats Lola ts 


An Gxocrimenuweseeonaucted by dePian and 
Grisamore to show the advantages of an averaging 
i I : 1 ., (44) 
circuit over a non-averaging single circuit. 
distribution of output values was obtained by 
oL ainge tae Sanc senal to both the 
averaging and the non-averaging circuits. After 


elaborate manipulation of the output data, the 


Polito miis  relartrons were found: 





Be 


For the non-averaging circuit (139 samples) 


O 02073 


Il 


O A 


For the averaging circuit (44 samples) 


O 0025 


x = 0.187 

re distribution curves for the two types of 
circuits are SNOWN Mime 4.3. As one can inter- 
l (Siro j jo TOL GO [Dr er ]ized distribution of 
ura sienals (x<) idei TA 3, the average circuit 
has a considerably smaller standard deviation. It 
can be concluded that in general, the averaging 
technique provides more reliable output signals. 
Db. Output Wavetorms 
| The improvement in signal quality of an 
averager output can be best seen from a set of 
altos cos or three noisy input 
signals and the resulting output are shown in 


a AA 


WnenFenls one input is- noisy, 
ene averacer output firs che same noise Function 
as the input, but reduced to one-third. 

if two of the input signals are noisy, the 


output noise level depends on the amount of 


correlation between the noisy functions on each 





Probability of x 


er 


eee en all three inputs are noisy, the out- 
put noise levels increase but are still less than 


those of any of the inputs. 


Normalized distribution of output signals (x) 


AVERAGING CIRCUIT 
(44 SAMPLES ) 








Arbitrary Units 


SINGLE (NON -AVERAGING) CKT 
(139 SAMPLES) 


0,05 9.10 0.15 0.20 0.25 0.30 0.35 0.40 


Fig, 4.3 





Averager Output 


RN teten 


nr Ning uhay jr 


Fig. 4.4 


Experimental time plots of averager output when 
one, two, or three input signals are noisy. In 
each case the upper three signals are the inputs 
and the lower signal is the output. 





ZR = 


Mw. technique 


A eo alte Lon 

A vote-taker is a generalization of the 
majority organ introduced by von Neumann. The output 
of a voter will always be the median value of the 
inputs. Voting operations in an analog system have 
already been performed in chapter 3. The operations 
bella voter circuitry on three 3-bit digital words 
wert be Conducted later in this section. 
Ze ¡implementation 

AS Sica dw he last chapter, the 
voting concept can be defined, in terms of Boolean 


algebra, as the following relations: ‘38) 


ec, X5.%,) = (4, Vy X4) A (4, Vv x) A (X, V X.) (4.1) 


where X X and X mare digital npa signals. 


fee > 3 

The above concept can be easily implemented using 
mime vOover circa: try Mown in Fig. 4.5. The circuit, 
in essence, produces an output which remains correct 
no matter in what manner a Single channel fails. 

Critics of the voting principle often ask the 
following question: How does the failure rate of the 
meuer arrect the overall probability of error in a 
waren? Obviously, if the voter is constructed of the 


Same components as used in the rest of the system, no 


muemrovemen. occurs. The next step is to consider using 





ee 


x, Jor > AND M 


Ple, 4.5 Voter Circuitry 


MNAE MEL relraple parwse Torzche vote, This in turn 
merollowed by the Ssugcestion that one should use these 
re mely reliable parts cor the rest of the system, 
Brereby creating the original condition with no increase 
fa reliability over the non-redundant case, The last 
suggestion is highly impractical, however, because 
Bene xıirtıies or modern cireultries and economic con- 
atenas often prohibit the use of ultra reliable 
components throughout the entire system. 

amerore, I cansbezcomeluded that IE only the 
voting circuitries are made of highly reliable components, 


mee, Overall system reliability will still improve. 





= (7G = 


Peet ombcarcalculatvonm Of tne improved reliability 
well be presented in the next section. 

Onemmmst realize that ene voter in Fig. 4.5 is 
only a 1-bit machine. It is true that in this thesis 
all signals are assumed to be 16-bit parallel words; 
fuera 16-bit parallel werd voting circuitry will take 
Mp several pages of circuit diagrams. In order to 
Mide the reader with the perception of what a 
LI U vote-taker would look like, however, a simpler 
ea. vöoter is shown in Fig. 4.6. 

a o ce binary words O11, 100, and 101 
w (Pro illustrate the operations of such 3-bIt 
momer. The purpose of the comparator is to assist 
meo OR gates to find the larger of any two 
3-bit words. As soon as any two bits have different 
Wes, the comparator will identify which bit has 
a value of i, then command the converters to SDE 
p rest of the 3 bits of the smaller binary word to 
mave che same values as those of the larger binary 
pan In this way, the "output at the OR gates will 
amays be the larger of the two 3-bit words. The 
key to Fig. 4.6 provides an example for such operations. 

Im zone Comp erco nue i C inputs with the output bit 
NE would mnouteezinar the output bits do not 


Mr esene tie majority Or che input bits. For example, 





ee 





Fig. 4.6 A 3-Bit Voter 


x o 





ewe 


KEY to Fig. 4.6 


Dinary Base 10 
E 5 
ere 1 10 6 
s. 7 
oe o ge a 
So oe» ta or 
ee To > ai, 


Operations of COMPARATOR at point A , 13% comparator 


ne 


top voter (other comparators operate in similar fashion): 


la T Xy 1 z X, 1? identity which is larger, otherwise 
no action taken. 
do If 211 > E command converters to convert Lo 2 
to have same value as X T aAa Convert X to have 
e 255 
same value as ur ° 
bee If pa X 1: commend converters to convert X10 
to have same value as X, o È and convert Ly 3 to 
have same value as X, 3° 
INPUTS OUTPUT 
IOn 


¡TO 110 (Median Value) 





De e Mp ıcant DIt on the output does met represent 
cmo Of the most significant bits on Ene three 
Wibubs. «he reader may have noticed, however, that tne 
output represents the median value of the three CO 
Sener examples performed by the author show similar 
meus. itm this regard, the voter in a digital system 
is identical to the mediator used in an analog system, 
Ss discussed in chapter 3. 
Di Rear ans Malntarnaprlirty 

Heresschenre krabener ns c.uovelszcondueted Tor 
Porsche averaging and the voting techniques for 
comparison. One of the Major advantages of the voting 
c ep is that it does not require any failure 
detection. Failure detection, om the other hand, is 
essential for some fault-tolerant systems that use a 
Weomcthance renewal Scheme, Gourpceernrtteure the system 
wound a faulty module using spare units, once the 
Parled module has been isolated. 

Wien a channel falls Bbyeouceutrine a faulty signal, 
it is sometimes not easy to determine the exact cause 
Acne fault; it can be a short or an open circuit, 
or a limit value such as a supply voltage. As long as 
ey a single channel has failed, there will be no 
effect on the output signal (for a triply redundant 


case). Moreover, monitoring equipment can be set up 





- 83 = 


S I s DP i l oy olan ae p yer a particular signal 
deviates from the other two. Once the faulty channel 
G 1located, it cam be serviced Om ine without affecting 
mec overall operation of the conurol system, provided 
Bm, chat a Second chamme] does not fall during the 
service period. As long as maintenance is available to 
menace te aulu ua, rh e probability of continuous 
failure-free service is greatly increased. 

in Gitcereitaoriity analysis, all input signals are 
Por j c c COP e zer tree, DUC to have the possibility 
Paeocime aa talse value. A false value at the input is 
demined as a failure Of en input Signal. A clear defini- 
mom Of AM sucpue Tallure is not established; instead, 
Ae probabile tha at least one, two, or three input 
signals have failed will be plotted as a function of 
Wdividual signal failure probability. 

il = pre bait e aa l east f out Of 3 inputs 
foil Pr(f), is the probability that f, f-1, etc. signals 
fail; based on the binomial expansion theorem, Pr(f) 


suchen be defined as do oe O) 


3 . E 
Pr(f) = Y —“=— p?* (1-p)°"* (4.2) 
pS ea | 
gi eden the probability of an individual input 


failure, 





Pr(f) 





Probability of Failure, 


O 0.5 1.0 


Probability of Individual 
subsystem Failure, P 


Fig. 4.7 


Probability that at least (1), (2) or (3) 
Signals are faulty vs. individual signal 
failure probability 


jJ lis. 4.7 the proposal Prize), that at least 
mor o Channels fail is plotted against the constant 
Emopaoility, P, that any one of the signals may be faulty, 
wep: = |, 2, 3. From this graph, one can obtain an 
meme acblOn of the failure probabilities for the averaging 
and the vote-taking ee 
everl applies only tonchee averager Since one of 


three channels fails for the voter has no effect on the 


wne For the averager, however, the output will be 





Mae any One Of the inputs is faulty. Curve 1 
Mac ates that the probabliity of a faulty output of 
Bove rager iS worse than the probability of failure at 
any single channel. Of course, the averager output 
Signal will not deviate as much as an individual signal. 

Curve 2 of Fig. 4.7 represents the case of the 
l Leer ‘in which a faulty output will result waienever 
fi ge oso LES three inputs are faulty. If the cmannel 
Mais Dy Open circuiting, however, the output will not 
ug ELN te DS shape of curve 2, it becomes 
ece clear that for well-designed channels with 
Be Zr, zhe probability of a faulty output for the 
mower is can small Ccomperecd with that for a single 
Paannel . | 

PiicliVecurvceorlNdicages the worst case when 
caes Channels are faulty. Until all three inputs 
are faulty, an.averager will still react to some extent 
mele correct signal as long as some information from 
Mee Signal get chrousn. The voter, on the other 
Paver wil Simply neglect the correct signal altogether 
as soon as two signals are faulty. 

Since the vote-taker can operate perfectly with a 
Rony or Channels failed, fast repair or replacement 
of a malfunctioned channel will sharply reduce the 


ee ability Of system failure. This feature is especially 





entita thermal power plant if one considers the 
eeomomic penalty associated with the shutdown of the 
Prant for maintenance of instrumentation. 

merirdentally, the fact that a voter maintains a 
pue ec OULDUL even when amininerity of ive channels are 
mem cy is a Simple example of faült>masking, the ability 
NE enana: meat from Deing transmitted further 
downstream. 
4. oe rental Verilicatron 

before seno enna cer LL 1s considers 

meaty easier tO visualize the sharp improvement in signal 
quality of a voter output from analog signals. Time 
Mis tot three noisy input signals ana the voter output 


meme seen in Fig. 4.8.5) 


Wien tonly one input is 
best the voter output is completely clean. 

i CwO Of ole Input Sena pore noisy, the output 
iSe level is directly related to the amount of 
morprelation between the noise functions on each input. 
b-beful examination of the output shows that the 
output waveform is identical with the noise-free signal 
Por one-third of the time. 

Paice ily when all tesse pulsare nolsy, the 
output noise levels increase, but similar to the averaging 


Monique, Une noise levels*are still less than those of 


moe inputs. 





ro 


Voter Output 


Mund aww 


Fig. 4.8 


Experimental time plots of voter outputs when one, 
two, or three input signals are noisy. In each 
case the upper three signals are the inputs and 
the lower signal is the output. 





= Coe 


SH Fear pn le, Tor Hisner Order Redundancy 


The triply redundant case has been used 
throughout the analysis. One must realize that higher 
Seder OL redundancy is also used. However, the triply 
meatumagant case is felt to be the most practical case 
because it is the lowest order of redundancy to which 
the voting concept may be applied. Obviously, one may 
easily extend all of the results for higher order 
redundant system in which Pr(f) may be represented by the 


Kol lowing formula: 


n : Š 
EAC) a p u n (4.3) 
i=f 


(= ee 
Ime n = Order of redundancy. 
Ds Nertziple Eine restoria gel nen 
in addiction Co ciee VOLer COntiguralion 
Min Fig. 4.5, there are Tonner voter configurations 
mau wlll yield higher reliability. Such an improved 
version is shown in Fig. 4.9. This arrangement is 


(47) it 


called the multiple line restoring element. 
Someists of a group of N voting elements, each with 
ugo. All of che lines trom the input bundle enter 


each of the restoring elements, M M and Mn 


Ea: = 
A more sophisticated technique is the triplicated 
(48) 


Wisiging method shown in Fig. 4.10. Eolie 


C Oh of the parallel channels into a large number of 





2 89 = 


N 
Í 


Output 
Bundle 


Input 
Bundle 


| 


N 


Fig. 4.9 Multiple line Restoring Organ 


MODULE 


D MODULE — 
@ MODULE 
on 


ç 
Ui 


MODULE 


2 


MODULE 


@ © E 
HEE 
l 
dc 


Fig. 4.10  Tripliicatedi Voting technique 





2 G0 = 


segments and taking a vote after each segment, it is 


Mowe pOssible for the system to experience a sizable 


number of faults in all three channels and still 


perform satisfactorily, as long as the faults do not 


occur simultaneously in identical segments of two out 


of the three channels. The number of such segments in 


70 
50 


30 


20 


MTBF Multiplication Factor 


mea stem is referred to as the ‘level of voting". $78) 
MTBF's vs. Levels of Voting 
° > 
° 
ys E 
«xX 
a 
RO ace 
0.90 
0.80 
3 5 7 lo 2o 50 100 200 


Level of Voting (n) 


Fig. 4.11 





2Co S 


Fig. 4.11 shows the improvement in reliability as the 
toting levels are increased in a parallel channel voter 
system. Assuming a non-redundant system with a 98% 
probability of non-failure, a three channel redundant 
Eerscem wrch two levels of voting should have its MTBF 
(mean time between failure) increased by more than 
Secemes. Of course, the higher the levels of voting, 
meen Sreacer will be the MIBF's, as indicated from 
Eig. 4.11. One must realize, however, that cost is an 
Mportant factor in determining the maximum level of 


eine that an engineer can design a system. 


wwe anced Voter Technique 
‘ee IGE ge eyble walleye 

Tn an@inscrumemuawienreconurol system that 
M ena Voting circuitry e eae Ome, examined in the 
bi cino Section, Whenever eeaeee Talis, the output 
will show considerable transient due to the switching 
action of the voter. Sometimes, these transients 
Ata be severe enouch to cause an adverse response in 
Me” total system. A new voter has been proposed to 
Penimi ze such switching transients; the output is 
determined as a continuous smooth function of the 
redundant inputs using a weighted e) 
2. Dranei pie sort Operations 


Dose pedone enne switching 





\ 


Segoe 


transients on the output because the isolation of a 
Day Channel is accomplished through a continuous 
numerical weighting. The output is determined in 
such a fashion that the outlying (faulty) signals 
mec heavily discriminated against, in favor of the 
signals that are fairly close. 

seccion tae auther pricrly menuloned an 
averaging method that assigns heavier weight factors 
to more reliable channels. These weight factors, 
ei. were determined a priori. The voter described 
cis section, on the other hand, uses weight factors 
Mat are dynamic and are continuously changing based 
on cross-channel di Ferenc cs o 


Aoc diagram orf Sucio er ls shown in Fig. 4.12. 





Fig. 4.12 Advanced Voter 


V is defined as 


Sur 
W.V. + WAV. + WAV 
y = J 1 DREI Deo (4.4) 


out _ 
Wy + Ws + We 





O vionsly, if W. = Wo = Wa = 1/3, then VE t will 


Simply be a mean value voter, or a Simple averager, as 
su q examined in section C. In any event, regardless 


of what values VW» Wo» and We take on V 


Mie ont nuous smooth function of Vi: Vo; and Vn: 


Reterence (43) provides a family of weight factors 


SUE is always 


mer a triply redundant voter. Some weight factors 
wolve the exponential functions, whereas Otcners are 
Meed in terms of the hyperbolic functions. One group 
ns c oh factors that iS of particular interest is the 


mon lowing: 


N 
1 Y, 2 LE 2 
W. = |] 1 + nn Bene I. 
1 
a 
ue 2 ie > Ve T 
W. = | 1 —— Se (4.5) 
a 
Ya esa, 2 We = 2 
TA LA —— 
x a a 


The constant a is the tolerance parameter which is 


< 


W 


w 


a measure of the allowable noise level in a given channel. 
Note that if the square of the cross-channel 


differences, (V; _ ve, are all small, then the equation 


OE | will approach the following: 


z _ V. + Vo - ur 
Out” 
3 








Í. 


AE 


Vi _ Vo 2 
On une Other hand, if | ——————_} << 1 and 
a 


Va -V 2 Vo V Ə 
both ==.) and — Pp TSE 


2 2 
i 
` Vi si Vo 
ue š 


equation OF Vou - 


+ reduces to No 


From the above analysis, it becomes clear that if 


V3 is indeed the erroneous signal, then the weight factors 


e computationally vote out Va MOR Ol the CWO 


nearly identical signals Vi and Vo. Table 4.1 can be 


Med. tO demonstrate just that. In this table computed 


= 1? Vos and Va 


are tabulated. Formulas used for V and W, to W 
UG il 3 


are equations 4.4 and 4.5, respectively. 


values of URR for a range of values of V 


ASICS reader Canseco Sec meten factors are 
constructed to discriminate against a possible failed 
m al in favor of the remaining good signals. In this 
besard, it is similar to the voter described in section 


D. 


Mmee@ectional Redundancy 


L. FAC rOductClon 

mhis section dcalsiwvith a reliability problem 
enS somewhat different Trom that of a voting element. 
Here the major concern is the improvement of the overall 
reliability of the entire system by partitioning the 


system into functional blocks and making each block 








— (064 


INPUTS OUTPUT 


0.1 O. 033 
Oro USO 
ene O. 210 
ae (n OO 
ee 0.174 
lea 0.114 
220 0,058 
3:0 OT OTS 
1.0 1.000 
de dl LOSS 
102 2.068 
To Jol o 
20, O 
3.0 10007 
4.0 12072 





Tl Voter Output for Triply Redundant Signals 





- 96 — 


parallel-redundant. 
2: Pripeiplesser Ope raipaons 
I em SDN Ob oh inn ovina the reliability 

a System is to establish a parallel configuration of. 
D icon ic al unfts, either both operational or one 
F rational and the other in standby, The disadvantage 
Of this arrangement is that the failure of any one 
component within the unit would place that entire unit 
Sou Of action. 

cher esvstem ler Dann daimte LuUnCtLOnal blocks, 
mar each block is parallel redundant, this would 
significantly increase system reliability because now 
PSone block in aset aller he other blocks in 


(49) The outputs of each 


mae SCL Can Still be used. 
menetional block are cross-strapped to the inputs of 

ene succeeding pair. A block diagram of such system 

IA Snown 1n Fig. 4,18, Tshessvysrem may be an encoder, 
Seeder, Or aly other Tumneeitemeal device in a control 

cememe, 

With the system parci croncd into [ive parallel- 
w-sundant functional blocks, 1t can now be configured 
into 2>, Sr 32 posciolencombina tions Of functions to 
Seecumvyent failures should they occur. Functional 


sections are activated by power switching. With 32 


Er Llc contigurations, there is little doubt that 





Zg = 


Stage A Stage B Stage C Stage D Ses 
A. = Failure Rate 
Fig. 4.13 Functional Redundancy 


Mees overall reliability of the system has been greatly 


mimoroved. 


Noise Reduction 


1. ME OLE on 
Signals from various instruments are usually 


Supecimposed with noise, Ine extraneous noise may be 


a result of thermal emf from an RTD; or it may be caused 


mee seli—neating in a thermistor, to name only two of the 
many sources. Chapter 2 contains a detailed description 
Soemary Of the sources that can generate noise in an 
Wwistrumentation system. 
DI, [lo Se peduetiornmetnodolocres 

Noise can be categorized into two groups: 


aldo or coherent. Random noise is usually generated 





= ice 


Anainn components, such as RTDs, transformer cores, or 
semiconductor junctions, whereas coherent noise is either 
locally-generated by processes, such as voter switching, 
or coupled in. Coherent noise often takes the form of 
"spikes". 

Regardless of the noise origins, several methods 
w C Oonmonly used to retrieve the original waveforms. 
Fame of these noise reduction techniques are analog-to- 
digital conversion, shielding and guarding, signal 
compression and filtering, and where possible, an 
information rate that has enough redundancy to allow 
Pied gital processor to retrieve data via correlation 
and nsn nito) 

Where noise is likely to have large spikes as a 
major component, the integrating-type A/D converter 
(dual-slope) usually provides additional filtering. 
mor random noise, if there are sufficient samples taken 
See given signal channel, the technique of averaging 
May be used as a filtering device. 
DE Technigue of Averaging 

Vers tiegdi=#s more dwerion technique 

often used in a digital system. A digital averager is 
bistcally a device used for averaging repetitive noisy 
Signals. Signal averaging has the ability to recover 


the signal's original waveshape from the noise. In 





sc 


this way, the signal-to-noise ratio can be improved 
D several orders of magnitude. 

Or Would Tike to, DOING OUuL Chat the averazer 
mentioned here is different from the averaging | 
Pert ptexing technique examined in section C. In 
section C the averager is a device that takes an average 
mee of the Signals from three redundant channels. 
merce, averaging is a technique that reconstructs a 
signal waveform by taking the average of a sufficient 
Wier Of repetitive noisy signals. In this regard, 
bWéi-W-vcrager described in section C, in addition to 
mmerove the reliability of the signal, also acts as 
se reduction device. Or course, the degree of 
Wes -Mrcduction is not as extensive as compared to the 
acer in this section since only three samples are 
taken (in a triply redundant case). 

movi ded cHe waver orna reBeabed Over and over 
m 7. any signal waveform which is corrupted by noise 
emmi be reconstructed. For a weak periodic signal that 
is buried in noise, the technique enhances it by over- 
Wing successive segments of the noisy signal, where 
aer seegment length equals the period of the a O 

Even when the waveform repeats itself at irregular 
Wecervals, but if some characteristics of the signal can 


be used to align the successive, noisy waveforms, aver- 





- 100 - 


aging can still be used. Fig. 4.14a and Fig. 4.14b 
illustrate such an example. The signal in Fig. 4.14a 

Mas a rather poor signal to noise ratio, but it contains 
a sharp peak which rises above the noise. By aligning 

the peaks and then averaging the noisy waveforms together, 
m noise will tend to cancel itself out whereas the 
Signal reinforces itself; the result is shown in Fig. 


4.14b. 


Averaging An Aperiodic Waveform 


an Ammann AS A— 


Fig. 4.14 a Fig. 4.14 b 


The averager uses each new noisy signal to update 
a partial average formed from previous waveforms, thus 
forming a new partial average. The sequence of events 


eam pe seen in Fig. 4.15, The symbols in Fig. 4.15 


are defined as gia 
e ¡She present noisy waveform to be averaged 
E is a sampled and quantized version of e 
A is a sampled and quantized version of the 


present partial average before it is modified 
DYTE, 





- 101 - 


Averaging System Waveforms 


Time 
-_———___———É- 


Flo 215 





= ieee 


di, Low-pass Filter for the Vote-taker 


Tewas shiewmn' in tche diccussion in section D 
that the output of a voter is rather jagged; the 
usss r o C ion of the voting circuitry is the cause 
moc ules high frequency spectral content. 
Fig. 4.16a represents a digital input with a broad 


(2) 


band noise spectrum. Note that the abscissa is in 
Fl Scale. Three input Signals with similar noise 
spectrum like that shown in Fig. 4.16a are fed into a 
voting multiplexer. The output after multiplexing 

(Fig. 4.16b) shows some fairly interesting effects. 

The overall waveform is en, smoother. At 

meme trrequencies, however, substantial harmonic contents 
meeesulll present. 

In Fig. 4.17a a digital input signal with a narrow 
end noise spectrum is shown. The Output after a voter 
Ns treated im hig. 2.175 mere, one cam see clearly 
miña there are definite peaks at integer multiples of 
Mie” fundamental frequency. 

ia a practical situation che signal spectrum and 
mee nolse spectrum often overlap, therefore, considerable 
noise can be filtered out by using a simple low-pass 
bewsfilter like that shown in Fig. 4.18. 


5. Bü tering of Para 


in the digital mode, one can conveniently 





- 103 - 


Broad Band Noise 


oN 


Fig. 4.16 a Fig. 4.16 b 
pes Noise 
Fig. 4.17 a Fig. 4.17 b 


Figo 4el8 RC Filter 





= love 


manipulate the time variable under various circumstances. 
After an analog signal has been converted to its digital 
form, time is no more constrained than any other char- 
INSISTO the signal. In fact, time canbe compressed. 
This process permits the collection of data at a slow 
rate and the output of this collected data ina fast burst. 
Berzesemple, when temperature Signals are picked up by 
e Dover aN interval of a Tew seconds, they can be 
eeomeressed and repeatedly processed or displaced every 
few Dee 30) 
If certain Gaussian noise is always present in a 
Paecicular Trequency band, while the signal itself 
spreads out in the entire frequency Sosemabiı, wWealsjel elas 
may wish to use a band-pass filter for noise reduction. 
Mimalbolcal telemetry, in addicion tO increase trans- 
fission erficiency, data compression is often used as 
ES AGUS tO reduce noise. oy using data compression, 
the amount of data to be transmitted is now reduced, 
K jj jn the form of redundancy reduction, variable- 
Emen encoding, or parameter extraction. If the 
remaining important data are reorganized at constant 
time intervals, a bandwidth compression is also 


Csi 752) 


achieved. lus Sp cita ue or data compression 


is now also acting as a band-pass filter. 





- 105 - 


DE Software Digital Filters 

Software digital filters refer to the different 
algorithms that one can use to implement a filtering 
operatlon on a general purpose digital computer. Some 
Ene better known procedures include the Fourier 
Transform, the Walsh Functions, and the Wiener filtering 
vechnicue. The lialsn Functions are particularly useful 
for non-linear ‘signals. Reference (53) provides more 


details in this area. 


H. n pl Example in Multiplexing 


In Fig. 4.19 the author has designed a simple 
triply redundant multiplexing system To illustrate many of 
F zröopies already discussed in the preceding sections of 


(50,54) Tie r J r n Ci pt eq Co De general 


enapter 4. 
enough so that its methodologies can be applied to most 
engineering systems. 

The signal levels out of many transducers ame usually 
mooie millivolt range, possibly 10 or 100 mV full scale. 
W addition, the transducers are often located in a noisy 
environment. In Fig. 4.19 it is assumed that the trans- 
ducer output is about 10:mV and that its two output leads 
me electrically isolated from ground. The cable leading 
from the transducer, however, is subject to capacitive 


Pmeamamductive noise pickup. 


By using shielded cable, most noise pickup can be 





BUTXOTATITINN UT oTdwexq eTdwtsS vV 6T’r *STA 


31A3( 
QOTUNY 


£—_oyeaedaes pelamod pue 


SISINPSULAA) 02 IX9U PAUIOJADA 





AV 1dSid 








TWOSIA 
| d 
a 
i A 
I 
-— zə 
Mh arms 1. IN T O č 
PILA 
YIDVYIAY a 0 
A = 
q L = l 
/v La = x 5 l 318V1Y VA 
Ss350%d 
SYILYIANOD 
118 -91 O Se. ae SA3INASNVUL 


SSyd -MO1 NOILYIN3SWAYLSNI 
1377 VYVA 








- 107 - 


iaa: however, common-mode noise may Still exceed the 
Lransducer output by several orders of magnitude. Common- 
mode noise is that component of the total noise picked up 
which is common to ez and en. [Peg Reel Sme JO role of the 
instrumentation amplifier to provide common-mode-noise 
rejection. Moreover, the amplifier amplifies the signal 
ej = €, and provides a high input impedance and a low 
Seeput impedance. 

The low-pass filter just upstream of the parallel A/D 
er is used simply to filter out any high frequency 
mera) contents in the original transducer signal. 
Sometimes, no filtering is needed because of the low-pass 
M@memactLCristics of the signal and noise or the input cable. 

The parallel 16-bit A/D converter used here has already 
meen alscussed at the end of chapter 1. The most evident 
advantage of parallel conversion is its tremendous speed. 
zen ormatrion no longer has to be converted bit by bit 
Bremse as the input changes, the output code also changes. 
With a parallel A/D converter, a sample and hold circuit 
memo longer needed. 

As mentioned in chapter 1, A/D conversion is performed 
Meer the signal source, and each instrumentation package 
is powered from a separate power source. After the signals 


Memes Deen converted from analog to digital, they are then 


Memmi toed to the control center for multiplexing. 





- 108 - 


Pee T CnC ee redundant signals are processed by the 
donec taker; the output will simply be the median value of 
Amer three input signals. The switching action of the voting 
eent will inevitably produce considerable spikes on its 
output, so a low-pass filter is needed here. 

Before the signal is sent on its last leg to the digital 
meter for display, it is processed through an averager 
(already examined in detail in section G) for further noise 
reduction. The digital signal can also be sent to a D/A 
eenn erter so that the analog output can be used in an 
analog control scheme, like the positioning of a valve based 
on flow signals. 

tneeauLchnor hopes that with the above example, the 
reader has acquired a better understanding of the various 
functions of a control system that uses redundant instru- 
mencation, and more importantly, how all of the components 
Mora together to enhance the reliability orf any noisy 
signal. 

In chapter 5 a case study of some of the control systems 


at the Deer Island Sewage Treatment Plant will be presented. 





- 109 - 


CHAPTER V 
DEER ISLAND SEWAGE TREATMENT PLANT - 


A REVISITED CASE STUDY 


A. Introduction 

The Deer Island Sewage Treatment Plant in Boston, 
Massachusetts presents a very unique case study in control 
systems engineering. In order to control pump speed at the 
Deer Island plant, flow and level signals from the three | 
headworks must be transmitted to the pumping station at 
Deer Island. These telemetered variables must be extremely 
reliable to prevent any massive overflows or even flooding 
at the pumping station. The control system at Deer Island 
employs an unique method to assure transmission reliability 
Brzchecking for any differences between the transmitted 
and returned signals. Here, "returned signal" refers to 
a signal that has reached its destination, but has now 
returned to its source. The reader will be introduced to 


this clever control scheme in the following pages. 


Bs System Description 


The Deer Island Sewage Treatment Plant is the larger 
of the two sewage treatment plants within the Metropolitan 
Sewerage District (MSD) in the Boston Harbor-Eastern 
Massachusetts Metropolitan Area. The Metropolitan Sewerage 


District comprises of 43 cities and towns, and 225-mile 





- 110 - 


network of interceptor sewers leading to processing facilities 


at the Deer Island and Nut Island (the un plant) sewage 


n plants. (8° 


Here, primary treatment is given to 
a combined average daily flow of 450 million gallons and a 
maximum daily flow of 1.2 billion gallons at these two 
plants. Wastewater from almost two million people and 
stormwater runoff from rainfall are processed to remove 
suspended solid matter and chlorinated to destruct bacteria, 
prior to discharge into Outer Boston Harbor. 

The next paragraph briefly describes the basic functions 
of the pumping station at Deer Island. 

A major portion of the flow from communities in the 
Boston metropolitan area located near the Mystic and Charles 
rivers empties into deep rock tunnels under Boston Harbor 
which carry it to the Deer Island Treatment Plant. The 
pumping station at Deer Island is required to lift flows 
from the deep rock tunnels, which are some 300 feet under 
Boston Harbor, into the treatment plant. The pumping 
station has a capacity of 810 million gallons per day. 

Professor Henry M. Paynter of M.1.T. has long been 
closely associated with the pumping station and its control 
systems at the Deer Island plant. In January 1982, the 
author visited the Deer Island plant and the Chelsea Creek 
Headworks for the first time. The visit was made possible 


only with the most congenial cooperation from Messrs. 





J 
1 


HA AA 





- 111 - 


Ken Donavon and Paul Sullivan of the Deer Island plant and 
with Professor Paynter as a most knowledgeable guide. Fig. 
5.1 shows a diagram of the entire Deer Island plant and 
basically how it ee. 

One must be selective in making a case study of a 
complex system like the Deer Island plant; therefore, the 
author intends to cover only some of the control systems 
which are relevant to this thesis. In particular, the 
areas that will be covered are the followings: 

i Sewage Tunnel System 

Qe Central Control Panel 

3. Digital telemetry vs. aging analog system 


4. Instrumentation for electric-driven pumps 


5. Instrumentation for future electrical generators 


C. Sewage Tunnel System 

The Metropolitan Sewerage District tunnel system 
is shown in a simplified schematic form in Fig. 5.2a. 
Here the dash components denote the flow and level-control 
action. The block diagram in Fig. 5.2b can be used to 
investigate hydraulic transients in such sewage-disposal 
system, as Paynter was called upon to perform at one time. 
The physical elements are interconnected as shown in Fig. 
5.20, (56,57) 


If a control scheme is designed so that the downstream 


flow Gc simply follows the inflow Qa, rather violent surges 


u 





| meer ota 
¿xx _—__ _m— O 
[ STIV4LNO 


` 
A 





NOTLY NIHOTHO 





JOVMIS 





‘1S QHYVM 
Va 








L 14VHS_ 3DVMIS Lar v3J513HD 


> JOVMIS MVH 
= 031V34138d 
| SAYOMOVIH 


NOILVALS 
ONIJWAd 





de 


INM HDNOHHL MO 14 JO Hl1Vd *<— 





“ALON 





T 2 ae Nae REEL WERBEN IN à > TN AENA 2 ry < SRA er ” ee f i EN 4 A E = 
=s ae a n : 0 A pi È È ° [- 3 Ber I 
| i pad RIN y F N Ris 
har + A =. š 4 rr Y Te 
N Y i = i = f v 2 METI ar 

i av : Pe eee ae p 2 ay ae eee a di ee SH to a ' È di oor Bee? iaa a 

È . < È ` ‘opto A , ad dr Ñ ra E t AO F EN - 2 e en E POY Le) ; x 

: # ` - et n s A ' 1 E — n ds Ve OS s 7 - Na ze PA. a A IEEE yep te! 7 JS 2 i E 

: Sd i sf > “a u "i re“ : g~ Ë $ = x Š > >> š : Web SE ; 42 TIN y Waya ee er edhe s n 4.17, eee | a y f: N zu a 

- de Des ERS lita dire A SOLARE arde del arto Rit nr) de i Vr nin .. or a SEELE seine RATA 4. [7 2 72 re i 


td rotte Mec co 





lo at M ST a N mE 
SE” Po le. = Br, pl 
RER 5s cid ee | A bs. 


- 113 = 


TELEMETERED CONTROL 


VARIABLES 


= 


Kb 


Sewage Tunnel System 


a 


Sere 


Pig, 





'B, iz 


É 
| 
È 


520 CoOmeuverenlock Diagram 


Rue, 





meer INFLOW (Qa) 


---- CAPACITANCE (A, ) 


> 
a 


INERTIA (1,) 


RESISTANCE (K,) 


# 
-į — 

i 

' 

i 

A 

` 


TELEMETERED | 


-CAPACITANCE (A,) 
I 
| 


CONTROLLED PULIPS (B 


—— 


B Ta 


ai 


Fio 5 420 


will occur whenever the flow is disturbed. Such heavy 
bronsients cannot be tolerated; thus the pumps at the Deer 
Island plant are placed under control of the following 
metemetered variables: 
(a) Input flow Ca 
(b) Upstream level H 


x 


(c) Downstream level Ho 
(d) Oucput Flow are 
Using the above variables, the pumps are constrained 


by the following relations: 


Qc = Ga = Q. 
d Q. d H, 
[| —— + Q. = By H, r Bo n == 
dt dt 
where Ba» Bos and T are controller adjustments, 





- 115 + 


An ASME publication entitled "The Dynamics and Control 


of Eulerian Turbomachines" ‘98? 


by Paynter provides an in- 
depth study of the actual control scheme for individual 
pumping units (inner loop of Fig. 5.2c). 

eS one can see, the reliability of the four telemetered 
variables is vital to the operations of the pumping station. 
Meene next section, the reader will be introduced to a 


sophisticated control panel (even in today's perspective) 


that monitors the reliability of the flow and level signals. 


D. Central Control Panel 

As mentioned in section C, flow and level signals 
are continuously used as part of a control scheme to 
regulate the speed of the pumps. A highly visible control 
panel that shows the quality of each flow and level signal 
is located in the main pumping station control room. From 
zen 5.1, it is clear that the Deer Island plant receives 
pretreated sewage from the three headworks, namely Ward 
street, Columbus Park, and Chelsea Creek. Accordingly, 
flow and level readings from the three headworks must be 
closely monitored. 

Since the six telemetered control variables must be 
transmitted from the headworks to the Deer Island plant, 
transmission reliability cannot be overemphasized. The 
Deer Island plant uses an elaborate control scheme to 


Mentor the reliability of the transmitted signals. Fig. 5.3 





- 116 - 


shows the operations of such monitoring ne) 


At one of the headworks analog signal from the flow 
instrument (Parshall flume) or level indicator (bubbler 
tube) is first converted into an air signal, ranging from 
3 to 15 lb. pressure. The air signal is in turn used to 
modulate a carrier frequency; this process is performed 
in the block labeled modulator. The modulated wave is 
then sent to the multiplexer for multiplexing before 
Wéspsmitted to the Deer Island plant. Here, the term 
"multiplexing" refers to the simultaneous transmission of 
several messages at different frequency bands over a 
common line. The signals from the headworks to the Deer 
Island plant are transmitted simultaneously on microwave 
Ma leased line. | 

At the receiving end at Deer Island, the received 
signal is first recovered by using band-pass filters in 
the de-multiplexer; the signal is then demodulated to 
retrieve the original signal. This analog signal is in 
turn converted to an air signal to be used as part of the 
pneumatic pump speed control system. 

The air signal mentioned above, in addition to being 
used to regulate pump speeds, is sent back to another 
set of modulator and multiplexer so that the signal can 
now be transmitted back to the headworks for comparison. 


At the headworks, the returned analog signal is 





SIG “STA 


aay  yaswy N33%9 
Mcrae, GG ici 
y/v/9 
WYYIV 
Py fannie CA EZ 
| iV 
pte} fe pees} Wr 
u YY TY 
| 


CASEN 





& Pese 


US 


(SIE) IV 


INIT] 43SV37 
az yaaq EIA 


SAYOMUVA H 


(asn ut ATQUeTIND) wesÁs KAds3a3əuəTərkL DUEISI 41990 


, 





- 118 - 


converted back to an air signal. Here, the air signal that 

has just returned is compared with the original air signal 

for any differences. The differences, if any, are indicated 

by a set of GREEN, AMBER, and RED lights. The differences 

in air signals are next transmitted back to Deer Island so 

that the control panels at both the headworks and the Deer 

Island plant have the same indications on their status boards. 
Fig. 5.4 shows the status board at the Deer Island plant. 

The three lights are defined as fo110w*90) (where tolerances 


are representative values only): 


CROEN —- < Í 1% 
PER a2 < L 5% 
ia 15 


If a red light stays on for more than one second, the 
system is designed to automatically switch to the alternate 
mede, either from microwave to leased line, or vice versa. 

A control panel such as the one used at the Deer 
Island plant greatly improves the confidence level of the 
Operator. For example, if al) lights are green, the operator 
knows that transmission quality is almost flawless. Even 
when one light is amber, as was the case during the author's 
visit, there is no need for urgency or immediate action; it 


may be the result of a minor problem, such as a faulty module. 





- 119 - 


Sut] psseoT 


SaN I a y 5 


O 0 O yw vas O O O 
©) © O Ad pee © © D 


Mo74 
45 quyu 


OOO Y PO 


SACMOLOTIN 


k 


g 


SFA 


pow = u 
aoquy = V 
UƏəd5 = D 
Sr Y Vago 


13437 


O ©) O 3342 VIS1IHO O e O 
O O O aa sum O O O 


13431 


OOO sam O O O 


SUTI posto SACTMOADTW 


pueog snae3asS pəpoo dOTOI 





- 120 - 


2, A Need for Newer Design 
As in any aging system, replacement parts often 

present the most insurmountable problem. Analog transmission 
equipment can still be replaced, although their digital 
counterparts usually have much higher availability and at 
considerably lower cost. Pneumatic control devices, on the 
other hand, are almost vanished from the open market. 
K placement parts are extremely difficult to be found. It 
would be economically infeasible to have each replacement 
made to its own specifications by a manufacturer. 

A digital system has many desirable features that make 
eeta natural choice eventually to replace the analog system. 
tme technique of pulse-code modulation is particularly 


MeeracLLvye, aS the reader will see why in the next section. 


F. Digital Telemetry 


L. Pulse-Code Modulation 

In digital communications, a multiplexed 
system often used is the technique of time division- 
multiplex (TDM) in which the signal messages are 
organized in subsequent time intervals, usually by 
sending one sample of each message after the other in 
a cycle or frame and sending one frame after the other. 
If each sample in the TDM system.is represented in 
digital form, a pulse-code modulation (PCM) multiplex 


is obtained. 





- 121 - 


The author feels that a digital telemetry system 
using pulse-code modulation deserves careful consider- 
ation as a replacement for the aging analog system. 
some of the characteristics that are inherent ina 
digital communication system make the PCM system 
considerably more desirable as compared to its analog 
counterpart. TIn addition, a decreasing cost of 
implementation due to the technological evolution in 
solid state digital integrated circuits makes such 
communication system all the more attractive. 

One of the important advantages of a digital system 
is its relative immunity to noise pickup. Any. noise 
picked up in transmission will ride on top of the pulse 
and / or produce grass between the pulses. However, 
as long as a pulse can be distinguished from the noise, 
there is no s pus 

Pulse-code modulation uses a binary digital code. 
The peak-to-peak value of the signal to be transmitted 
is divided into a number of discrete steps. The number 
er Dito Used in the binary code determines the total 
number of steps available and the accuracy of the 
transmitted values. For example, a 16-bit digital word 


provides 215 


Or 65,536 steps; Clearly, the smaller the 
value each step corresponds to, the higher the accuracy. 


Reference (61) provides a more in-depth explanation on 





- 122 - 


POM, 
Obviously, a 16-bit word provides considerably 

more accuracy than, for example, a 3-bit word. However, 
the transmission of 16-bit signals require a much 
greater bandwidth. In order to minimize bandwidth while 
maintaining accuracy, several techniques have been 
employed., One method involves the use of adaptive data 
compression, also referred to as "redundancy reduction". 
In this technique, any sampled data which would not add 
significant value to the received information is 
considered redundant and need not be transmitted., As 
a result, the sampling rate is sharply reduced and so 
is the bandwidth. More on this subject in the actual 
implementation of such system. 
2a Implementation 

Fig. 5.5 shows a block diagram of a digital 
telemetry system using digital filtering, data compression, 
error Control coding. The author considers such 
system a viable choice to replace the aging analog 


en. P) 


As before, flow and level signals will be 
transmitted from the three headworks to the Deer Island 
plant, except now that transmission is via digital 
telemetry with pulse-code modulation. 


Even with the new digital system, there is no 


reason to replace the color coded status light panel. 





Soi 


i n Sti Y300730 YoLy1ndON YIXIISLLIONN 
NoiLywyodni | vive -3q -30 


JA1393 
-3Q E È 






N 

I 

° 

= yaxaid "SSIIJWOD ya3113 YILYIANO) 

| Y3LLIWSNVIL Pie YoLvINCTOW y3d0) V LVQ WALID a/v 

WANIIS 
yY3INASNVYL 
IN 


NOILYWI1SI 





14919395 


uə[ysKs KaaəuƏTƏərLr TEeITSTa MON 





= eas 


Petucw4y, the status lights are so useful, yet so simple, 
that the people at Deer Island have become quite fond of 
them. Thus, the status board will be incorporated into 
the new digital system, still indicating the differences, 
if any, between the original signal (no longer an air 
signal) and the returned signal. In fact, it is practical 
to simply connect the digital system in parallel with 
the analog system; then, with the flip of a switch, the 
operator can have the control system operate on either 
modes 

ISO UNC Gree DLEOCKksS?s “digital filter, 
data compression, and spectral estimation all perform as 
a team to regulate the bandwidth of the signals being 
transmitted. The digital filter (usually a low-pass 
filter) prefilters the telemetry signals in such a way 
that the following data compressor can operate in the 
most efficient way. As mentioned earlier, data comp- 
ression reduces the amount of data to be transmitted by 
removing all redundant information. If the remaining 
important data are reorganized at constant time 
intervals, the number of sampled points are greatly 
reduced. By this technique, it has been found possible 
eo reduce the number of sampled points by at least a 
5 to 1 ratio, and in some cases by as much as 160 to 


uns reducing the number Of samples taken, the pulses 





= 125 - 


per second of modulation are reduced, and the bandwidth 
required is decreased. 

spectral estimation is a rather useful method to 
perform short-time spectral estimation, and thereby 
adapt the sampling frequency to a more appropriate 


value. ($1) 


In general, the sampling frequency is kept 
at the minimum possible value consistent with the 
signal frequency content in order to reduce the amount 
of data sampled. 

When pulse modulation is used, energy is transmitted 
only during the pulse sampling intervals. With data 
compression and spectral estimation, the sampling rate 
is sharply reduced; therefore, the transmitter duty 
cycle is quite low, and the overall transmission 
efficiency is greatly improved. 

Error control coding, a technique that uses the 
coder and decoder, performs a protective measure on 
the transmitted signals. Before the data entering 
the communication channel, suitable control data 
(a given number of bits in an information word) are 
added by the coder. At the receiving terminal, the 
ne control data are utilized by the decoder to 
detect (error detection) or correct (error correction) 
the errors introduced by the communication channel or 
(51) 


other disturbances and interferences. 


4 





Piewreader May Nave noticed that the technique 
Pie hrorm control coding performs a. function that is 
Similar to that of the status lights, to assess the 
quality of the transmitted signals. Therefore, if 
she status lights remain asi an integral part of the 
new system, coding the transmitted signals may not 
be needed. Of course, one can always use it as an 


extra redundancy. 


G. Wise tt Cleny Lnstrumentavtomumnon the Electric-Driven 

Pump 

Gar renelv, chere äarezırnespumnps at ine Deer Island 

upo station. Eight pumps are run by diesel engines, 
while the ninth pump is a variable speed electric-driven 
pump powered by on-site generators. With the U.S. diesel 
pessime technology in its present state, it is difficult 
Ku Oct the industry to come up with new design to replace 
the aging machines. A few years ago, an electric-driven 
pump was installed so that its performance can be evaluated 
n possible future conversion to all electric ee 

If the instrumentation panel for the electric pump is 
mended to be a prototype for future models, it is a very 
disappointing one. There are only two or three instruments 
Gn tche electric pump control panel as compared to almost 


ten instruments on the diesel instrumentation panel, The 


information that one can obtain from the electric pump panel 





A 


Gm une overall plant operations is totally insufficient. On 
ble other nand, the diesel instrument panel shows a substantial 
amount of plant data. Shaft levels and flow rates from all 
wee neadworks can be seen clearly in a quick glance. in 
dedition, whether a particular unit is pumping from Chelsea 
Creek or Ward St. - Columbus Park is shown in plain view on 
w panel. If an operator, while facing this panel, has to 
make a sudden decision during a plant upset, he has all of 
the necessary plant data to act upon. 

From the above discussion, it becomes clear that adequate 
Miecrumentaction Similar to that on the diesel control panel 


meet De installed on the electric pump instrumentation panel. 


i Ererrumentatıon Lor Future Electrical Generators .- 
At the present, the five on-site generators provide 

KE Og electrical power for the single electric pump 
and the auxiliaries (sewage treatment, lights, auxiliary 
pumps, etc.). If more electric-driven pumps are used to 
replace the aging diesel engines, considerable more elect- 
rical power must be needed. This in turn will require 
more electrical generators to be installed. One proposal 
Ives the installation of several gas turbine generators 
using methane gas as fuel (methane gas is a byproduct from 
the decomposition of sewage sludge). 

Wieihncregenehusés gas turbines or diesel engines for 


S@ectrical generation, proper control systems and adequate 





- 123 - 


eu rementation must still be provided. The triply redun- 
dant multiplexing system shown in Fig. 4.19 is a good 
starting point for the design of such control system using 
redundant instrumentation. As in any thermal power plant, 
Baie parameters monitored will be temperature, pressure, flow, 
and possibly density. 

In chapter 6, some particular aspects of instrumentation 
errors will be examined. Chapter 6 is different from 
enapster 2 in that chapter 2 dealt with instrumentation errors 
and uncertainties in a survey format, whereas chapter 6 will 
discuss some of the methods that one can use to compensate 


for these errors. 





- 129 — 


CHAPTERSVI 


PAYS ITCAL CONSTRAINTS IMPOSEDSBY CONSTITUTIVE 
AND CONSERVATION RELATIONSHIPS: 
IMPLICATION FOR INSTRUMENTATION REDUNDANCY 


A. Introduction 
sometimes instrumentation readings that obviously 

Meo CO be density or temperature corrected are still being 
used without either correction. And occasionally, instru- 
ment data that clearly violate laws of conservation are 
Still being recorded and interpreted as if they were correct. 

The area of physical constraints imposed by constitutive 
and conservation relationships is another promising area 
for redundant instrumentation. However, due to lack of 
time and general unavailability of sufficient literature 
in this area, the author will only attempt to present a 
Sumsoory treatment of this subject matter. A few brief 


examples will be given later in this chapter. 


P. Bensity Correction 


ds Computation of Density from Pressure and Temperature 


An excellent example to illustrate the fact 
that some instruments need density correction is the 
differential pressure (d/p) cell. The d/p cell is used 
to measure flow rate in either a liquid or gas medium. 


The differential pressure caused by the velocity increase 





- 130 - 


is proportional to the square of the flow rate. More 


specifically, the Bernoulli equation leads to the 


following flow rate relationship: 42) 
V (flow rate) = Q= AV = AQ >> (6.1) 





Fig. 6.1 Differential Pressure Cell 
From equation 6.1, the following mass flow rate (M) 
expression can also be established: 


AP 


p 


M = Fnean 9 — J P mean À P ED 


Clearly, Pi and Po can be measured experimentally, 





Qu (6.2) 


as indicated by the pressure taps in Fig. 6.1. If 
fluid properties are also known, one would only need 
temperature to compute density. With AP, O , and 


A (physical dimensions of orifice plate), the actual 





mass flow rate can be easily calculated. Since T, is 


usually not equal to T thus temperature measurement 


1? 


here refers to an average value of T, and T,. More 


1 2 
on temperature correction in section C. 


Ch Actual Measurement of Density 

Since T, is normally not equal to Ti» Py will 
Bew@atferent from y 2° Inererore, Dorch Ps and  » 
must be measured to obtain a more correct value for 
density. Again, here a more correct value could simply 
be the mean value of O, and Po As for density 
Measuring device, one can use the vibration type liquid 


densitometer described in chapter 2 to measure the two 


density values. 


C., Temperature Correction 


As mentioned in the last section, T, and T, 


Fig. 6.1 do not normally share the same value. The following 


of 


paragraphs will briefly explain this phenomenon. 

AS the fluid passes through the orifice plate, some of 
the kinetic energy (no matter how infinitesimal) will be 
lost due to impingement of the liquid on the plate. This 
loss in kinetic energy is usually recovered in the form of 
heat, or a slight increase in temperature on the orifice 
mee and in the fluid. Therefore T, will no longer be 


the same as 1). 


Since some of the total energy is lost at the orifice 





- 132 - 


plate, the total energy at point 1 (H, ) must be greater than 
the total energy at point 2 (H,), or AH = H, - H, SO 
Since one can assume with reasonable accuracy that |AH| 

is proportional to the change in internal energy, |4U| , 

it can be un oa that T, ~ Ty Seo san SUM athe Situation 
in Fig. 6.1 can be expressed as zer: 163) 


Lf AH = H, - H, > O 


and Jan] ~ laul 


then T, - I, 7 tO es 


AS one can see, in order to get a more representative 


value for temperature,. both T, and T, must be measured. 


DI How to Minimize Data Error in a 2-Phase Region 


isa Pro T; and Ti are measureed values 
Vapor 
Interface 
Region 
ieee crete 


Fig. 6.2 2-Phase Region 





~ 133 - 


Io e please region tske that shown in Fic. 0.2, 
it is often difficult to determine true temperature and 
pressure. The two procedures described in the following 


paragraphs should prove to be quite valuable in minimizing 


(63) 


data error. The reader should be aware of the fact 


that the two correlation procedures will not produce 
identical results. One method will normally produce a more 
accurate result than the other, as the author will illustrate 
with a Simple example. 

beocedure 1 


a. Determine Te (P,,) and ze. (P. ) 


b. With the four data points: TCP)» TP)» T 


and T minimize error by the following methodology: 


L? 


ye 


4 
let E(error) = ) (Wy, E T 
k=1 


where W. are weight factors based on confidence 


level of each measurement, 
2 


£ 2 2 
(OTT) 
Sa Leni. 


then E k Tk 


2 2 


ve wann +ar 


Minimizing E yields: en = 0 


2 P 


2 i AL 


MUTI, 
4 


c. Since this is a saturated state, if T. is known, 


at 


P can be determined. 
sat 


= 








Procedure 2 


a. Determine aes (T,,) and Beer (T,) 
bee Witch ve (T 5 Po (Tr), LE and Pi? repeat part b 
o PProcedure 1 to find P A 
sat 
Lf Pre is known, Tan can be easily found. 


E. An Example in Minimization of Data Error 

For this example, the 2-phase medium is assumed to 
be saturated vapor and liquid at 400.0°F and 247.26 psi. 

In the vapor region, due to the insulation effect of a steam 
blanket, pressure can normally be measured with greater 
accuracy than temperature; therefore, the following contamin- 
ated values of pressure and temperature and their weight 


factors (W's) are assumed: 


£ O 
P_ = 248.00 psi RS SONE 
P, = 246.20 psi mos AO 
MEL E (a Wo 
CO MS Oe 


in order to determine temperature values given pressure 
measurements, or vice versa (as required by procedures 1 & 2), 
the method of interpolation is often used if one needs to 
determine values that lie between tabulated data in a steam 


table. However, the results obtained from such method are 





- 135 - 


rarely reproducible. With the advent of digital computer, 
the technique of analytical curve fitting becomes practical. 
Moreover, the results are always reproducible. 

One can use the following procedure to fit the saturation 
curve analytically. In this procedure an algebraic expression 
is determined by performing linear regression on several data 
Faces from the saturation curve. Once determined, this 
algebraic relationship can be used to generate pressure values 
based on temperature inputs, or vice versa. 

If a transformation is performed on the two parameters, 
pressure (P) and temperature (T), two new variables can now 


be defined as follow: 


X = L_ where T is absolute (6.4) 
T 
Y = in P (6.5) 


With the two new variables, one can easily use the 
following linear laws for curve fitting the saturation line: 


x b v | (6.6) 


Vor Com d) Xx (647) 
where a, b, c and d are constants that will be 
determined. 
The reader should be aware of the fact that if only 
two data points are used to fit the saturation curve, 
m@emo.cal curves will result by either correlation method 


ees. X or X vs. Y). 





- 136 - 


Using five data points from the saturation curve and the 
technique of linear regression on each of the two equations 
(6.6 € 6.7), the following values for constants a, b, c and 


d were determined: 


a = 3,27 x 107° 
Beene 107" 
err=. 158550 
ee: 


Thus equation 6.6 and 6.7 can now be rewritten as follow: 


Elm sa ak lo C2604 x Io) Tn P (6.8) 
T 
licia G. (6.9) 
T 


With equations 6.8 and 6.9, one can proceed to procedures 
1 and 2 in this example. 
Breoceedure 1 

a. Using equation 6.8, the following temperature values 


are found: 


; O 
T__+ (P,) = T_ (248.00 psi) = 400.27°F 
2 O 
T oat (PL) = T, (246.20 psi) = 399.63°F 
Ë D 
be Tor = ES where T, = T. (P.,), T. (P,), 
Ty and Ti 


Using the weight factors assumed earlier, 


T becomes AORO F. 
sat 





= 137 - 


Ce- -With Tane 400.01°F, using equation 6.9, 


eae 


247227 O 


Procedure 2 


a. Using equation 6.9, the following pressure values are 


determined: 
O a 
O 3 
PATO (T,) = Po (401.50 F) = 251.50 psi 
Nien 
b. Psat s Where P. = P. (T.), P. (Tr) 
Pur and Pr 


Using the weight factors assumed earlier, DEE 


becomes 247.29 psi. 


c With Roe = 247.29 psi, using equation 6.8, 


T 400.02°F 


sat 


As the reader might have observed, the temperature and 
pressure values deduced from both correlation procedures are 
almost identical to the true values, ` However, one should 
be aware that such closeness between these two sets of values 
has been partially due to a coincidence in correlation between 


the contaminated values and their respective weight factors. 


Da Redundant Parameters - T, P, O 


in this section, the technique of using redundant 


parameters to minimize data error will be discussed. (63) 





- 138 - 


As the reader knows, any one of the three parameters, T, P, 
and © can be considered as redundant, and any two of the 
three parameters can be used to compute the value of the 
third redundant parameter. Furthermore, the computed value 
can then be used to check on the accuracy of the actual 


measurement. This procedure is illustrated as follows: 


3 Í s% (vapor) 
I 
3 = 2% (liquid) P. 
+ 
3 - 2% E Po 
3 = 5% po DA 
A a) pr) O pm) 
Range of measured computed 
Measurements values values 


(The range of measurements is based on readings from 


three redundant instruments). 


A general procedure to minimize measurement errors is 
described as follows: 


1. Measure Ta? P and O p Experimentally 


m?’ 


2. Compute To? P and a and use these as the adopted 


a’ 
values for T 


and p 


adopted’ P adopted’ adopted 


3. Formulate the following least squares error expression: 





- 139 - 


j2 


2 
È ) 


Let E (error) = W. (P. =- P Tara ut 
P m a 


1 m 


m» and “Yo are weight factors based 


wiere N 
P 
on standard deviations of instrument readings. 


4. Minimize error by the following equations: 


s rs = 0; = = 0; O n O. 


Š DE 2 Tp, 
However, tche expressions riound for P., T _ , and P 
a a a 
hist Bezsubjeer Lo CDE ONS raint of the state 


equation, © (Pas Tas (as = 0 


See list distribute corrections so as to reduce errors 


based on constraint. 


The Role of Conservation Laws in Measurements 


All engineers know that the laws of conservation, 


such aS mass conservation, momentum conservation, and energy 


conservation can never be violated. However, instrument 


readings that clearly violate these laws are often still 


beams recorded. 


béé-Wcolkowing three Drier exkanples exemplify some typical 


Situations in which the instrument readings might be left 


error if the specific relationships are violated: 


l1. Conservation of Mass 


M = S Hion Da Flow. ut (6.10) 


n 





- 140 - 





Fb 
| —T 
YF = time-averaged 
measurement of 
flow 
ea 
Fa —> a: — Four 


Z. A ÓN 


Pig. 6.3 Flow Measuremenc 


ES 6.0 Ge Summon Bes and F, at any time t 


D 


is not necessary equal to F AO Me veni one takes 


out 
mien taime—averaced measurements Of the three flows, 
Enin Che accuracy of the instruments, the following 


relationship should always hold: 








1 T —— 


A = YF Gore) 


out 

If the above relationship is violated, then the 
ENS DS Must be distributed acecordimeaiy among the three 
flowmeters. Reference (64) provides an in-depth study 
Si many of the commonly found ftlowmeters. 


2. Conservation of Momentum 


eZ Dai Force, pn - Y” Force CO?) 


OUT 


For any flow in the direction indicated as shown 





a = 


Fig. 6.4 Pressure Measurement 


Mo A P Rs be greater than P If the 


1 2 ° 


oec Sure Sensors indicate diriferentiy, one or both 


instruments must be in error and need to be adjusted. 


Saturated Steam 


Cold 
Water 





m m 
water water 


Condensate 


Fig. 6.5 A Simple Heat-Exchanger 


= = 


3. Laws of Thermodynamics 


Example 3 as illustrated in Fig. 6.5 is a much more 
complex case. Careful energy and heat balance calculat- 
ions must be performed before any violation of thermo- 
dynamic laws can be a 

By the first law of thermodynamics, the following 
expression is true: 

(h h (6213) 


(h ) 


M team steam ` a = Mater Hu 7 cw? 


Clearly, specific data such as mass flow rates 
(m's) and enthalpies (h's) are needed for the energy 
balance calculations before any given instrument can be 
isolated as faulty. 

in addition, if one considers the second law of 
thermodynamics, then the following relationship in 


terms of entropy (s) is always true: 





x IS (6.14) 
steam “cond * | ater HW > |fistean | steam * 
Paster | Scy (6.15) 


One must realize that although the heat exchange 
between the system and surroundings can be assumed to 
be zero, an increase in entropy is to be expected, 
Because the process is basically irreversible. 


It should be clear to the reader that concern for 





= ieee 


the physical constraints imposed by laws of nature is 
indeed an important aspect of redundant instrumentation. 
Only occasionally are attempts made by engineers to 
distribute instrument errors consistently within a real- 
time system. Much more work remains to be explored 


in this area, 





LOR 


i, 


AS 
REFERENCES 


Avizienis, Algirdas, "Fault-Tolerance: The Survival 
per ibute Of Digital Systems," Hroceedinestof the 
bagi, Vol. 66, No. 10 (October 1978), pp. 1109-1125. 


¡EMO Dean ©. and Bender, Erich K., "Frequency 
ErTeets in Analog Channels Multiplexed for Reliability," 


Bmeccedings Or the 1967 Joint Automatic Controls 
Conference, 1967, pp. 447-453. 


Breuer, M. A. and Friedman, A. D., Diagnosis and 


Reliable Design of Digital Systems, Woodland Hills, 


rss omputrer Sscience#*Press, 1976. 


Denning, KR. VW., Nowak, J. S., and Tuomenoksa, L. S., 
ONO. 1 ESS Maintenance Plan," Beli System Technical 
Journal, Vol. 43, No. 5, Part 1 (September 1964), 
pp. 1961-2019. 


Eızmeorctchy, C. V. and Chang, L. C., "System Modeling 
mea Lesuing Procedures for Microdiagnostics," IEEE 


Transactions on Computers, Vol. C-21, No. 11 (November 
Mew), pp. 1169-1183. 


eee. Wi. C., “Imeory and Use of Checking Circuits," 


Computer Systems Reliability, Maidenhead, England: 
MmmaeOcechn Information Ltd., 1974, pp. 413-454. 


Kuu J. E. and Macri, F. J., “Multiple Redundancy 
Baelicavlons in a Computer,” Proceedings of the 1967 


Annual Symposium on Reliability, Washington, D.C., 
January 1967, pp. 553-562, 


io were E; C Computer Redundancy: Design, Performance, 


QuieWFfucure," IEEE Transactions on Reliability, Vol. R-18, 
No. 1 (February 1969), pp. 3-11. 


Sheingold, D. H., Editor, Analog-Digital Conversion 
Demes, Norwood, MA: Analog Devices, Inc., 1977. 


Emo, Harmon H., Editor-in-Chief, Temperature, Its 


K urement and Control in Science and Industry, 
we Duren, PA: instrument Society of America, 1972. 


come we. R., "AN Evaluation of Industrial Platinum 
Resistance Thermometers," in Reference 10, pp. 971-982. 





J. 


do, 


14. 


15. 


O. 


de, 


18. 


iS, 


20. 


21. 


22. 


ale 


24, 


ole 


26. 


See 


DS E RODNE J., "Ihe Influence of Crystal Defects in 
Platinum on Platinum Resistance Thermometry," in 
Reference 10, pp. 937-949. 


k-eNediet, Robent P., Fundamentals of Temperature, 


Pressure, and Flow Measurements, New York: John Wiley 
& Sons, 1976. 


Sıderson, A. C., "Carbon Resistance Thermometry," in 
meretrence 10, pp. 773-783. 


siobhpson, W. L. and Anderson, A. C., Review of Scientific 


mistruments, Vol. 42 (1971), p. 1296. 


Scemirem, J.r., omratfiman, C. A., and Neighbor, J. E., 
Review of Scientific Instruments, Vol. 37 (1966), p. 499. 


NORIA. DIM, Flotow, H. E., and Schreiner, F., Review 


G 5 j i Pic Instruments, Vol. 38 (1967), p. 159. 


isj S A. 5,, Selman, Ge L., and Rushforth, R., 


Platinum Metals Review, Vol. 14, No. 3 (1970), pp. 95-102. 


NE E Evning, C. Le, and Miller, R. RL, Review 


of Scientific Instruments, Vol. 33 (1962), p. 1029. 


Pea AS I. and Fiock, E. F., Transactions of the ASME, 
vol 71 (1949), p. 153. 


orn, C Mos SAE Paper No. 524F, April 1962. 


uc man R., "Measurement of che Temperature Profile 


in a Laminar Flame," Proceedings of tne Fourth Symposium 


Pigiconbustion, 1952, pp. 259-203. 


Fili j. S U Ledford; R. L., and Smotherman, W. E., 


AGARDOgraph No, 145 on Wind Tunnel Pressure Measuring 
Techniques, London: Harford House, 1970. 


Deere, Glenn F., Editor, Iranmsducer Compendium, New 
York-Washinston: Instrument Society of America, 1969. 


ss rs Hermann K. P., Instrument Transducers, Oxford, 
agland: Clarendon Press, 1963. 


Dummer, G. W. A., Variable Resistors, London: Pitman 
Eness, 1956. 





C7. 


28. 


a9. 


30. 


DE, 


22., 


=>. 


34. 


36. 


27. 


38. 


SS 


MA 


res on L., "A Miniature Electrical Pressure 
Gage Utilizing a Stretched Flat Diaphragm,"' Langley 
mora, Virginia: NACA TNe2659, April 1952. 


taa W. G., Piezoelectrieity, New York: McGraw Hill, 
1946. 


Mena Literature on the Vibration Type Liquid Density 
Measuring System from the YOKOGAWA Company, Japan. 


Konemann, John, “Probabilistic Logics and the 
s TILhesis Of Reliable Organisms from Unreliable 

Components," Automata Studies, Princeton, N.J.: 

Deinceton University Press, 1956. 


nase, ee, On Computaple Numbers," Proceedings of 
the London Mathematics Society, 2-42 (1936), pp. 230-265. 


s oC We Oo. ana Pitts, W., “A Logical Calculus of 
mace races immanent 1n Nervous Activity," Bulletin of 


Mathematics and Biophysics, 5 (1943), pp. 115-133. 


Pater, Henry M., Analysis and Design of Engineering 
W emne: Cambridge, MA: The M.I.T. Press, 1961. 


Poi Ibrick, George A., "A Palimpsest on the Continuous: 
Electronic Representation of Nonlinear Functions of 

w ales, G: A. Philbrick Researches, Inc., Boston, 
HA, 1955, 


Bememcnoach, Hans, Phe Theory or Probability, Translators: 
wnest E. Hutten and Maria Reichenbach, Second Edition, 
Berkeley, CA: University of California Press, 1949. 


Er enb700m, Paul, The Elements of Mathematical Logic, 


li York: Dover Publications, 1950, 


POSE. L., American Journal of Mathematics, Vol. 43 
roel), p. 182. 


Benter, Henry M., "Ordering and Selection Processes 

and Ultra-Reliable Systems," Paper (Figures Only) 
Presented to the American Association for the Advancement 
of Science, Session on General System Theory, Washington, 
bee, 1958. 


Amic RI Chard H. and Mann, William C., Editors, 


Redundancy Techniques for Computing Systems, Washington, 
Bees ss sopertan Books, 1962. 





40. 


41. 


42. 


43. 


44, 


4D. 


46. 


47. 


48. 


49. 


50. 


ol. 


a2. 


= ug = 


Willie James C., "Competitive Evaluation of Failure 
DEL CIONTALgorichms Lor Strapdaown Redundant Inertial 
Me cr ramento, Journal of spacecraft and Rockets, 
Neotel. Nonny (July 1974), ppi 529-529. 


heyoeve N., "Fault-Tolerant Design of Local ESS 


oc one, P Prococdinecs of the IpEE, Vol, 66, No. 10 
(October 1978), pp. 1126-1144. 


Penco, W. H., “Adaptive Vote-Takers Improve the Use 
epee aumaency,' 1n Reference 39, pp. 229-249. 


Bree, R. B., "New Voters for Redundant Systems," 


rae Of Dynamic Syscems, Measurement, ana Control, 


March 1975, pp. 41-45. 


wee Olmos and Grisamore, NT., “Iwo Approaches 
EPomlnMeerponrarting Redundancy into Logical Design," 
MaRe erence 39, pp. 379-3388. 


KOP D, C. and Bender, E: K., “Multiple Sensors 


sns; AQUA ty, Control Engineering, Vol. 13, 
lew (July 1966), pp. 68-73. 


Aa wemojOoy. MW. B. ana Root, W. Ls, An Introduction to 


the Theory of Random Signals and Noise, New York: 
McGraw-Hill, 1958. 


Mann, William C., “Restorative Processes for Redundant 
@Cemputine Syscems,” in Reference 39, pp. 267-234. 


. rhiiip J., “Redundancy Utilized to Boost 


Metropole cy,’ Aytation Week and Space Technology, 
ucbruary 5, 1962, pp. 72-75. 


WENES, Roy J. Jr., "Functional Redundancy Assures 
Q ara System Reliability," Electronics, March 15, 


er ocman, John B., The Design oí Digital Systems, 
New York: McGraw-Hill, 1972. 


wopoctlini, Vs, Constantinides, A. G., and Emiliani, 


ee a ters and Their Applications, London: 
Academic Press, i978. 


NS, Ve, Lotti, F., Ori, C., Pasquini, C., and 
Pero. F,. “Application of Some Data Compression 

(I Cod to ESRO Satellite Telemetry Data," Alta 

Rec mensa. VOL. 43, NO. 9, pp. 673-681. 





>. 


54. 


>. 


57, 


58. 


29. 


60. 


61. 


62. 


63. 


64. 


„427,2 


Walmsley, W. M. and Evans, W. A., "A Walsh Analyzer Tor 
Phase and Amplitude Measurements on Networks and Systems," 


Per C sm; Torpe COMperence on Digital Instrumentation, 
temach.. NWevemoer 1973, pp. 281-187, 


Meantanan, E., "The Principles and Design of Digital 


Neri Dos truments,' Proceedings of the Joint 


Senrerence on Digstal Mebaeoes or Measurement, Canterbury, 


moeland, July 1969, pp. 167-197. 


Commonwealth of Massachusetts, Pamphlet on "Metropolitan 
sewerage District," Boston, MA: Metropolitan District 
Senmtssion, 1976. 


boe, DD. and Paynrer, H. M., "Computer Represent— 
ations of Engineering Systems Involving Fluid Tran- 
sients," Transactions of the ASME, November 1957, 

pp. 1840-1850. 


piece PPM © . anerkoscenbers, R.C., Analysis and 


Simulation of Multiport Systems, The Bond Graph Approach 


Beer aysical System Dynamics, Cambridge, ‘MA: The M.I.T. 
Press, 1963, 


eo... “The Dynamics and Control of Eulerian 


Kurbomachimes,'" Journal Of Dynamic Systems, Measurement, 
ame Control, May 1972, po. 1-3. 


Her sonal Communications with Professor H. M. Paynter, 
er. 72 Cambridge, MA, February 1982. 


emcee TOur OL the Deer Island Sewage Treatment Plant, 
Winthrop, MA, January 1982. 


ran. Je J... Communications Electronics Circuits, 
Record tion, san Francisco: Rinehart Press, 1966. 


K neuben M., Essentials of Engineering Fluid 


Seña artes, Third Edition, New York:  Intext Educational 
Publishers, 1973. 


Personal Communications with Professor H. M. Paynter, 
URT., Cambridge, MA, April 1982. 


eure. Chuck L., "A Survey of Flow Instrumentation," 
A Course 2.996 Special Project Under the Supervision 
Sumeromcssor H. M. Paynter, M.I.T., Cambridge, MA, 
May 1981. 





DO. 


Db. 


awa 


en 00, Werren H., Thermopmysres, New York: Van 
Neocuramta netminolda Company, J971. 


NS and elman, G L., "some Eftects ol 
p Jonie ron tne Performance or Noble Metal 
Thermocouples," in Reference 10, pp. 1633-1662. 





=- 150 -= 


APPENDIX ET 


VARIOUS TEMPERATURE AND PRESSURE SENSORS 


A. Platinum RTDs 

Platinum, being a noble metal, is used almost 
exclusively for precision resistance thermometers. Platinum 
resists corrosion and chemical attack under most environments, 
so it is fairly stable. In addition, it is easily workable 
and can be drawn into fine wires. Moreover, platinum has 
a high melting point (1772°C) and in fact, shows little 
volatilization below 1000°C. All this is evidenced by a 
linear and stable resistance-temperature (R - T) relation- 
ship that characterizes the platinum sensor over a wide 
range of temperatures. An early example of a platinum 


RTD from the National Bureau of Standards is shown in Fig. 1. 


DI Carbon Resistance Thermometry 
Le Advantages and Disadvantages 


The carbon resistance thermometer has a number 
of desirable qualities as a secondary thermometer, 
including high thermometric sensitivity, small physical 
size, fast response, ease of installation, and very 
low cost. The major drawback, however, is that there 
is no well-defined theoretical (or empirical) resistance- 
temperature relation for use in extrapolation or 


interpolation. As a result, a somewhat laborious 





_- 151 - 


calibration procedure is usually required throughout 


the temperature range of interest. 





EVACUATED 
SPACE 







SENSITIVE 
HELICAL COIL 






PYREX TUBE 
(3/3 iN. 0.D,) 


MICA CROSS FORM 


Pao ee Cons chicuLen vaeuall Of a platinum 
resristaricerthermometer cip 


a EiL ectcSs Om khacnetic biela 


Experimental data showed that the magnetic 
field effect is strongly dependent on temperature and 
becomes substantially larger as the temperature is 
reduced, It is interesting to note that the effect is 
independent of whether the magnetic field is applied 
parallel or perpendicular to the resistor axis. 

In a time varying magnetic field, the effect may 
be considerably more severe. Eddy currents may be 


intcrodúced in the leads which, by Joule heating, warm 





= 1527= 


the thermometer above the temperature of the surround- 
ings. This is especially true if the leads have a 
solder coating. The solder alloy may become super- 
conducting, but with a transition spread over a wide 
temperature range. Therefore, the resistance of the 
solder coating can be quite small over a considerable 
range of the magnetic field and may result in a large 


dissipation of power. 


Op Germanium Resistance Thermometry 


Besides carbon thermometry, a second major category 
Of semiconductor resistance thermometry is the germanium 
resistance thermometer. The germanium thermometers share 
some of the inherent problems with the carbon thermometers, 
such as self-heating errors, but it does have its own 
Unique characteristics. 

Germanium, in its intrinsic form, is a rather poor 
resistance measuring device in the cryogenic region because 
its dR/dT is so large, and its resistance at a temperature 
approaching absolute zero (0 Kelvin) is so great. However, 
solid state physicists have utilized the idea of mixing two 
ersmore elements to form an alloy which would reduce both 
the near zero Kelvin resistance and the sensitivity to 
GR/dAT. Impurities are commonly introduced into germanium in 
the form of pure elements. Some of these elements include 


phosphorus, gallium, and arsenic. 





- 153 - 


Noble letal Thermocouples 


T: Environmental ovabi bio; 
(66) 


Darling and Selman conducted a series of 
experiments in which the environmental stability of 
noble metal thermocouples was investigated in a system- 


atic manner. In particular, they studied the compati- 


bility of the platinum metals with oxides such as 


alumina, magnesia, zirconia, and silica. Their experi- 


mental results indicated that the reactions between 
platinum and the refractory oxides are contrel led by 
the affinity of platinum for the metal released on 
decomposition, by the surface area of the reacting 
substances, and by the rate at which oxygen and metal 
vapors can be removed from the reaction zone. 
2. Chemical Reaction 

Metal oxide decomposition involves a process 
of dissociation which yields both metal and oxygen in 
gaseous form. In the case of aluminium, the reaction 
can be described as follows: 

NS A O 


2 3 2 


Alumina dissociates, oxygen is evolved, and platinum 


—> 4/3Al +0 


extracts metal from the refractory to form dilute 
alloys. Experimental data confirmed that platinum has 
a much higher affinity for zirconia and alumina than 


for magnesia. One proposed postulate to explain this 





Lu m 


phenomenon is that the magnesium-magnesia dissociation 
pressure is higher than the vapor pressure of platinum, 
whereas the metallic vapor pressures of zirconium and 
aluminum lie well below that of platinum. Most of the 
reaction processes occur through a vapor phase and 
proceed rapidly only when oxygen is continuously removed 


from the reaction zone, 


E. Variable Resistance Pressure Transducers 

A diagram that illustrates the basic operating 
principle of the variable resistance pressure transducer 
is shown in Fig. 2. The pressure to be measured is applied 
to the force collector (capsule) which, through a linkage 


rod, moves a sliding contact (wiper) across the electrical 


signal Lead (Wiper) 


Capsule 

(Force 
Linkage Collector) 
Rod 


Pivot 
x Pressure 
KILL 





Sliding Contact Wiper 


“ VITTO Resistance Wire Coil 


Excitation or Other Resistance 
Element 


Fig. 2 Potentiometric Pressure Transducer Schematic 


/ 





- 155 - 


resistance wire windings. This action in turn produces a 
resistance change between the wiper signal lead and an 
excitation lead. Therefore, with the wire excited as shown, 
a voltage change between the wiper and excitation lead can 
be developed. This change is linear for most transducer 
designs. A nominal full-scale deflection for such a system 
is about two percent of the capsule diameter. In order to 
obtain large deflections, two or more capsules may be 
cascaded so as to add tne deflections of each. 

Besides using a capsule, a bourdon tube can also be 
used as a force collector., The bourdon tube is a spring 
ey tube with an elliptical cross section which is closed 
at one end and is shaped in a curved or twisted configuration. 
When pressure is admitted into the tube, the difference in 
area exposed to the pressure causes the curved tube to tend 
Mc arenten. Thus, if the open end is held securely, the 
ased end will move. The bourdon tubes can generally 
provide greater deflections than capsules. Many transducer 
designs incorporate the spiral, helical, and C-shaped 
bourdon tubes because of their large deflections which in 
some cases permit transducers to be built without an extra 
linkage between the tube and the resistance element. This 
minimizes vibration, friction, and backlash problems. 

The resistance element of a potentiometric transducer 


most frequently consists of electrical wire wound on a 





~ 156 - 


Mandarel. The wire is generally a platinum alloy on the order 
of 0.001 — in diameter, whereas the mandrel is an insulating 


material such as ceramic or phenolic. 


E. Strain-Gage Pressure Transducers 


Most strain-gage pressure transducers have a 
confipuration like that shown in Fig. 3. This is the so- 
called bonded strain-gage technique that consists of four 
active strain-gage elements bonded to the elastic element 
(cantilever). When a force is applied as shown, the two 


top strain gages (1 and 2) are in tension and increase in 


| Diaphragm 





: Pe 
N Cantilever Beam 


orain 
Gages 


Fig. 3 Bonded Strain-Gage 
Cantilever Transducer 
resistance while the bottom elements (3 and 4) are in 
compression and decrease in resistance. By connecting the 
two elements whose resistance increases (1 and 2) and the 
two whose resistance decreases (3 and 4) in diagonally 
opposite arms of a bridge as shown in Fig. 4, maximum 


output is obtained. 





- 157 - 


POWER 
INPUT 





SIGNAL | 
OUTPUT 


Fig. 4 Bonded Strain-Gage 
Electrical Connection 


io ceceno ne veve the advent of semi- 
conductor technology, it has become advantageous to manu- 
facture strain gages from semiconductor materials. The 
semiconductor gages have a gage factor that is approximately 
L eos greater than that of a wire gage. Gage factor is 
defined as the ratio of normalized resistance change to 
unit change of strain. With a substantially higher gage 
factor, manufacturers are now able to develop smaller and 
extremely stiff pressure sensors, allowing high frequency 
dynamic measurements to be made more conveniently and more 
c rately, 


Besides the more familiar bonded metal wire strain-gage 


- 158 — 


configuration, there are several other types of strain-gages; 
some of the examples are gaged diaphragm pressure transducers, 
cantilever-type transducers, pressure vessel transducers, and 


unbonded strain-gage pressure transducers. 


Ge Diavhragm-Type Variable Reluctance Transducers 





A variable reluctance pressure transducer commonly 
Wsed in the power industry employs a diaphragm as the 


elastic element and is shown in simplified form in Fig. 5. 


Pressure Port 






Magnetic 
Core Tiiductance Coll 1 


Pressure Sensing 
Diaphragm 


| Pressure 


Fig. 5 Diaphragm-Type Variable Reluctance 
Pressure Transducer 
A diaphragm of magnetic material, supported between two 
inductance core assemblies, completes a magnetic circuit 


with the cores. The diaphragm deflects when a differential 





- 159 - 


pressure is applied to the pressure ports. This increases 
wear gap in the magnetic flux path of one core while 
decreasing the gap in the other; therefore, the reluctance 
of each flux path is altered. The overall effect is a 
decrease in inductance of one of the wire wound coils and 
an increase in the other. A half-bridge, two-active-arm 
device is formed if the two coils are connected as shown 


meerig. 6. 


Coil 1 






SIGNAL AC EXCITATION 


COIL 2 


eS GEE tical Configuration 

ftor Variable Reluctance 

Pressure Transducer 
Fa meezocleccuric Pressure Transducers 

Most piezoelectric elements will reach a Curie 

Meee when heated, AT this Curie point temperature, the 
crystalline structure changes, polarization is lost, and 
hence the piezoelectric effect is destroyed. Quartz has 
a Curie point of approximately 1000°F, whereas this temp- 
erature for some of the ceramic elements is as low as 


250°F. In adention, quartz has a negligible pyroelectric 





- 160 - 


effect which is defined as the changes in output that are 
Psl onal to the change in temperature experienced by the 
crystal. It is for these two reasons mentioned above that 
pre quartz element is particularly more applicable in areas 
of temperature aie and high operating temperatures. 
Ceramic elements, on the other hand, have a charge 
density that is generally 10 to 100 times greater than 
Met for quartz; as a result, ceramic elements are often 


used in situations where low pressures are measured. 




















© 
Lok 


Thesis ih Q Q L 

L8263 Louie 

Cel Control systems 
reliability using 
redundant instrumenta- 
tion. 


jiii 


dE mits Geant 


il lI | I 





